Cisco Talos Exposes JWR, a Chinese PhaaS That Steals Card Data via Encrypted WebSockets
Cisco Talos researchers have published an analysis of JWR, a sophisticated Chinese-language Phishing-as-a-Service framework capable of stealing credit card details and credentials in real time. The framework lures victims through SMS messages disguised as toll fees or delivery notifications, directing them to fake Shopify or WooCommerce checkout pages that closely mimic legitimate storefronts. JWR uses AES-CTR encrypted WebSockets to stream keystrokes to attacker-controlled servers before the victim even clicks submit, while attackers remotely control screen transitions using over 40 commands to prompt OTP entry, secondary card details, or banking app approvals. In environments where WebSockets are blocked, the framework falls back to HTTP long polling, ensuring persistent communication with the command-and-control server. Security teams are advised to monitor for suspicious SMS-linked domains, long-lived binary WebSocket connections, Web Workers, and the framework's distinctive REST API endpoints as detection signals.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in