Cisco Talos has identified a new, previously undocumented real-time phishing framework named "JWR," which appears to be a variant of "The Outsider" phishing-as-a-service platform. This framework employs an open WebSocket connection, allowing attackers to monitor victim keystrokes live and dynamically guide them through fraudulent checkout and login processes.
JWR is currently being deployed through SMS-based lures that impersonate regional toll and postal authorities. Its operators leverage this real-time interaction to steal sensitive information, including payment data, two-factor authentication (2FA) codes, identity documents, and device fingerprints.
A key concern with JWR is its ability to bypass multi-factor authentication (MFA). Because the attacks are operator-driven in real time, threat actors can prompt victims for 2FA codes precisely when needed, overcoming this common security measure. The extensive volume of data collected by JWR provides attackers with comprehensive identity profiles, which can then be used for further fraud and network compromises.
The framework's seamless integration with legitimate e-commerce platforms, such as Shopify, makes these phishing lures highly convincing to unsuspecting individuals. This sophistication underscores the challenge in distinguishing malicious activity from legitimate online interactions.
In response to this threat, experts recommend prioritizing user education, particularly regarding SMS-based phishing (smishing) that involves unsolicited messages about deliveries or toll fees. Organizations should also monitor for unusual authentication attempts, as stolen device fingerprints and session tokens can be used to bypass conditional access policies. Implementing phishing-resistant MFA methods, such as FIDO2 hardware keys, is also advised.
Cisco Talos has provided a complete list of indicators of compromise (IOCs) and coverage updates for JWR on its blog, enabling organizations to enhance their defensive measures against this evolving threat.






