
Smishing Triad Outsider Cluster Deploys the JWR Real-Time Phishing Cockpit Threat Campaign
Indicators of Compromise
No domains found for this campaign
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
REMEDIATION&DETECTION
Technique-level detection guidance, with MITRE ATT&CK detection strategy identifiers where published.
ID | Technique | Detection focus |
|---|---|---|
Phishing (Mobile) | Monitor brand-abuse and smishing telemetry for newly registered lookalike domains, short-link redirection chains, and carrier-reported message floods. | |
Spearphishing Link | Correlate customer-reported SMS lures with passive DNS and certificate transparency issuance for brand-adjacent names. | |
User Execution: Malicious Link | Alert on managed-device navigation to newly observed domains that immediately load a /static/js/main.js bundle. | |
Obfuscated Files or Information | Flag client bundles carrying javascript-obfuscator.io string-array shufflers together with the JwrCrypto or WorkerCrypto symbol (DET0087 covers the encoded-payload strategy). | |
Encrypted/Encoded File | Detect application/octet-stream bodies with a fixed 48-byte header followed by 16-byte-aligned ciphertext. Strategy DET0087. | |
Deobfuscate/Decode Files or Information | Any captured envelope decrypts with the in-band prepended key, so retain full packet captures for analyst decryption. Strategy DET0275. | |
Debugger Evasion | Hunt for self-referential toString().search() integrity probes and catastrophic-backtracking regex traps in served scripts. Strategy DET0371. | |
Virtualization/Sandbox Evasion | Look for clients reporting document.visibilityState upstream, used to time challenge injection. Strategy DET0046. | |
Browser Information Discovery | Detect early user-agent and browser fingerprint collection posted before any user submission. Strategy DET0013. | |
System Location Discovery | Alert on sequential client-side calls to ipinfo.io, ipapi.co, ip-api.com, and httpbin.org/ip from one page load. Strategy DET0043. | |
Input Capture: Web Portal Capture | Monitor integrity of public checkout and login pages, including WordPress and Shopify plugin and theme changes. Strategy DET0480. | |
Automated Collection | Detect per-keystroke POST cadence to a single endpoint during form entry. | |
Command and Control: Web Protocols | Hunt the /api/open/ path prefix and co-occurrence of the endpoint set on one host. Strategy DET0027. | |
Non-Application Layer Protocol | Inspect binary WebSocket frames on /webSocket/QT/ paths, and the fixed 2-second long-poll cadence used as fallback. | |
Symmetric Cryptography | Signature the AES-256-CTR envelope shape rather than the payload, since keys are random per message. | |
Non-Standard Port | Baseline outbound port usage and alert on Cloudflare-fronted non-standard ports from user endpoints. | |
Exfiltration Over C2 Channel | Treat a POST to the_final_interface or addCvv on an unknown host as confirmed data loss. Strategy DET0348. |
Immediate remediation for a confirmed victim session: treat every field the victim may have typed as compromised, including a second card if a decline prompt appeared. Cancel and reissue cards, reset the affected bank, brokerage, email, and PayPal credentials from a clean device, revoke active sessions and mobile wallet tokens, and place issuer-side monitoring on the account. Where identity documents or handheld ID images were submitted, initiate identity-theft monitoring, because the kit collects exactly the artifacts needed to defeat know-your-customer re-verification.