Campaigns
Smishing Triad Outsider Cluster Deploys the JWR Real-Time Phishing Cockpit

Smishing Triad Outsider Cluster Deploys the JWR Real-Time Phishing Cockpit Threat Campaign

JWR Phishing KitSmishing TriadOutsiderPhishing-as-a-ServiceSmishing
A high-volume smishing operation attributed to the Chinese-speaking "Outsider" operator cluster is delivering the JWR phishing kit, a real-time, operator-driven credential and payment-card harvesting framework deployed inside the wider Smishing Triad Phishing-as-a-Service (PhaaS) marketplace. Victims receive SMS lures impersonating national land transport authorities, postal services, couriers, toll operators, and banks, then pass through a multi-stage funnel that captures identity data, full card data, PINs, bank and PayPal credentials, and one-time passcodes while a human operator watches the session keystroke by keystroke over an AES-256-CTR encrypted WebSocket channel.

Indicators of Compromise

No domains found for this campaign

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION&DETECTION

Technique-level detection guidance, with MITRE ATT&CK detection strategy identifiers where published.

ID

Technique

Detection focus

T1660

Phishing (Mobile)

Monitor brand-abuse and smishing telemetry for newly registered lookalike domains, short-link redirection chains, and carrier-reported message floods.

T1566.002

Spearphishing Link

Correlate customer-reported SMS lures with passive DNS and certificate transparency issuance for brand-adjacent names.

T1204.001

User Execution: Malicious Link

Alert on managed-device navigation to newly observed domains that immediately load a /static/js/main.js bundle.

T1027

Obfuscated Files or Information

Flag client bundles carrying javascript-obfuscator.io string-array shufflers together with the JwrCrypto or WorkerCrypto symbol (DET0087 covers the encoded-payload strategy).

T1027.013

Encrypted/Encoded File

Detect application/octet-stream bodies with a fixed 48-byte header followed by 16-byte-aligned ciphertext. Strategy DET0087.

T1140

Deobfuscate/Decode Files or Information

Any captured envelope decrypts with the in-band prepended key, so retain full packet captures for analyst decryption. Strategy DET0275.

T1622

Debugger Evasion

Hunt for self-referential toString().search() integrity probes and catastrophic-backtracking regex traps in served scripts. Strategy DET0371.

T1497

Virtualization/Sandbox Evasion

Look for clients reporting document.visibilityState upstream, used to time challenge injection. Strategy DET0046.

T1217

Browser Information Discovery

Detect early user-agent and browser fingerprint collection posted before any user submission. Strategy DET0013.

T1614

System Location Discovery

Alert on sequential client-side calls to ipinfo.io, ipapi.co, ip-api.com, and httpbin.org/ip from one page load. Strategy DET0043.

T1056.003

Input Capture: Web Portal Capture

Monitor integrity of public checkout and login pages, including WordPress and Shopify plugin and theme changes. Strategy DET0480.

T1119

Automated Collection

Detect per-keystroke POST cadence to a single endpoint during form entry.

T1071.001

Command and Control: Web Protocols

Hunt the /api/open/ path prefix and co-occurrence of the endpoint set on one host. Strategy DET0027.

T1095

Non-Application Layer Protocol

Inspect binary WebSocket frames on /webSocket/QT/ paths, and the fixed 2-second long-poll cadence used as fallback.

T1573.001

Symmetric Cryptography

Signature the AES-256-CTR envelope shape rather than the payload, since keys are random per message.

T1571

Non-Standard Port

Baseline outbound port usage and alert on Cloudflare-fronted non-standard ports from user endpoints.

T1041

Exfiltration Over C2 Channel

Treat a POST to the_final_interface or addCvv on an unknown host as confirmed data loss. Strategy DET0348.

Immediate remediation for a confirmed victim session: treat every field the victim may have typed as compromised, including a second card if a decline prompt appeared. Cancel and reissue cards, reset the affected bank, brokerage, email, and PayPal credentials from a clean device, revoke active sessions and mobile wallet tokens, and place issuer-side monitoring on the account. Where identity documents or handheld ID images were submitted, initiate identity-theft monitoring, because the kit collects exactly the artifacts needed to defeat know-your-customer re-verification.


Observed Countries250

AD (504)
AE (186)
AF (986)
AG (698)
AI (566)
AL (608)
AM (637)
AO (39)
AQ (32)
AR (153)
AS (673)
AT (760)
AU (687)
AW (926)
AX (636)
AZ (186)
BA (899)
BB (844)
BD (614)
BE (23)
BF (291)
BG (371)
BH (582)
BI (244)
BJ (107)
BL (126)
BM (592)
BN (858)
BO (676)
BQ (851)
BR (849)
BS (144)
BT (201)
BV (321)
BW (713)
BY (835)
BZ (685)
CA (980)
CC (429)
CD (205)
CF (849)
CG (751)
CH (996)
CI (105)
CK (989)
CL (63)
CM (283)
CN (964)
CO (48)
CR (122)
CU (410)
CV (497)
CW (400)
CX (94)
CY (699)
CZ (168)
DE (532)
DJ (393)
DK (223)
DM (137)
DO (63)
DZ (470)
EC (783)
EE (418)
EG (745)
EH (782)
ER (680)
ES (573)
ET (56)
FI (42)
FJ (647)
FK (616)
FM (272)
FO (140)
FR (888)
GA (324)
GB (188)
GD (161)
GE (844)
GF (264)
GG (973)
GH (59)
GI (355)
GL (12)
GM (589)
GN (262)
GP (148)
GQ (524)
GR (637)
GS (508)
GT (929)
GU (233)
GW (770)
GY (609)
HK (986)
HM (686)
HN (584)
HR (73)
HT (474)
HU (456)
ID (161)
IE (400)
IL (258)
IM (20)
IN (108)
IO (302)
IQ (729)
IR (970)
IS (556)
IT (315)
JE (283)
JM (205)
JO (763)
JP (93)
KE (425)
KG (634)
KH (672)
KI (703)
KM (809)
KN (907)
KP (755)
KR (228)
KW (18)
KY (952)
KZ (47)
LA (707)
LB (58)
LC (276)
LI (704)
LK (435)
LR (814)
LS (450)
LT (742)
LU (60)
LV (901)
LY (910)
MA (710)
MC (963)
MD (726)
ME (452)
MF (820)
MG (511)
MH (58)
MK (321)
ML (232)
MM (396)
MN (124)
MO (18)
MP (603)
MQ (280)
MR (874)
MS (561)
MT (457)
MU (773)
MV (144)
MW (483)
MX (107)
MY (781)
MZ (379)
NA (7)
NC (362)
NE (309)
NF (76)
NG (50)
NI (346)
NL (259)
NO (605)
NP (313)
NR (449)
NU (757)
NZ (430)
OM (122)
PA (167)
PE (443)
PF (678)
PG (339)
PH (848)
PK (682)
PL (739)
PM (219)
PN (965)
PR (69)
PS (663)
PT (35)
PW (545)
PY (643)
QA (805)
RE (824)
RO (715)
RS (957)
RU (594)
RW (943)
SA (366)
SB (589)
SC (228)
SD (149)
SE (356)
SG (892)
SH (42)
SI (484)
SJ (998)
SK (577)
SL (217)
SM (121)
SN (244)
SO (968)
SR (795)
SS (921)
ST (239)
SV (793)
SX (829)
SY (878)
SZ (526)
TC (624)
TD (299)
TF (193)
TG (850)
TH (780)
TJ (501)
TK (651)
TL (788)
TM (426)
TN (799)
TO (301)
TR (925)
TT (960)
TV (196)
TW (510)
TZ (18)
UA (779)
UG (420)
UM (55)
US (358)
UY (413)
UZ (232)
VA (547)
VC (239)
VE (440)
VG (74)
VI (406)
VN (341)
VU (348)
WF (934)
WS (980)
XK (620)
YE (889)
YT (701)
ZA (497)
ZM (573)
ZW (597)