New 'JWR' Phishing Kit Offers Real-Time Attack Control to Threat Actors
A new phishing platform, dubbed 'JWR,' has emerged, providing threat actors with real-time control over social engineering attacks, according to researchers at Cisco Talos. This sophisticated kit livestreams the phishing page to the attacker as the victim enters information, enabling the attacker to manipulate the victim's experience and maximize the damage. JWR is designed to harvest comprehensive payment card data, login credentials, and personally identifiable information (PII) documents and images in real time. Its client-side engine impersonates login and checkout flows of various payment gateways, including Shopify, PayPal, Apple, Klarna, and several banks. The operator can stealthily control the victim's session through an AES-CTR encrypted WebSocket channel, allowing for the exfiltration of sensitive data such as credit card numbers, CVV, PIN, expiry dates, Social Security Numbers (SSN), passport or ID images, two-factor authentication (2FA) codes, website logins, PayPal credentials, and device fin...