Real-Time Phishing Kit JWR Targets Payment Platforms with Live Keystroke Monitoring

Real-Time Phishing Kit JWR Targets Payment Platforms with Live Keystroke Monitoring

First seen 18 Aug 2026, 12:02 UTC CybernewsGbhackers 78% similarity 66.5

Article Content

Browse articles
ThreatCluster

Cisco Talos researchers have identified a new phishing kit named JWR that allows attackers to monitor victims' keystrokes in real-time. This kit can impersonate major platforms like PayPal and Apple, enabling attackers to harvest sensitive information such as card numbers, passwords, and 2FA codes before submission. The framework operates through an AES-CTR-encrypted WebSocket connection, providing attackers with dynamic control over the victim's experience. JWR has been observed in phishing campaigns linked to SMS messages in Southeast Asia and the Middle East. The kit's capabilities include reconstructing shopping carts from real data, making it difficult for victims to distinguish between fake and legitimate pages. Researchers have identified 44 phishing pages and over 40 distinct commands issued from the command-and-control console. The scope of the attack is extensive, targeting not only payment details but also identity documents and full device fingerprints.

Key Points: • JWR phishing kit enables real-time keystroke monitoring for credential theft. • Attackers can impersonate major brands, complicating victim identification. • Phishing campaigns have been linked to SMS messages in Southeast Asia and the Middle East.

ThreatCluster AI How this analysis works

Timeline

2026-08-16
Cisco Talos uncovers JWR phishing kit
Researchers revealed the capabilities of the JWR phishing kit, which allows live monitoring of victims' keystrokes.
Cybernews
2026-08-18
Gbhackers report on JWR phishing-as-a-service
Gbhackers published details on the JWR framework, emphasizing its real-time operation and encryption methods.
Gbhackers

Community

Browse all →

Tracked Entities in This Story