Skip to content
Smishing Triad's JWR Kit Targets Victims via SMS Phishing

Smishing Triad's JWR Kit Targets Victims via SMS Phishing

First seen 16 Sep 2026, 19:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 22:55 UTC
  • The JWR phishing kit is used in a large-scale smishing campaign targeting sensitive information.
  • Victims are lured through SMS messages impersonating trusted entities, leading to phishing domains.
  • The Smishing Triad operates as a marketplace, with various actors involved in the phishing ecosystem.

A large-scale smishing campaign has been linked to the Smishing Triad, utilizing the JWR phishing kit to steal sensitive information including payment card data, OTPs, and online banking credentials. Victims receive fraudulent SMS messages impersonating trusted entities, prompting them to click on links that lead to disposable phishing domains. The JWR kit operates as a real-time fraud platform, allowing operators to dynamically adjust the phishing flow based on victim responses. Group-IB has attributed this activity to an operator sub-cluster known as Outsider, which participates in a broader phishing-as-a-service ecosystem. The campaign has affected numerous individuals across multiple countries, with the potential for significant financial losses. The JWR kit is noted for its sophisticated architecture, employing Vue 2 single-page applications and encrypted WebSocket communications for data exfiltration. This ongoing threat highlights the need for enhanced public awareness and defensive measures against smishing attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-01-01
Smishing Triad identified
The Smishing Triad was recognized as a significant threat actor in global phishing campaigns, with over 194,000 malicious domains reported.
Group-IB
2026-09-14
JWR phishing kit analysis published
Group-IB released a detailed analysis of the JWR phishing kit, revealing its operational methods and architecture.
Group-IB
2026-09-16
Gbhackers report on JWR campaign
Gbhackers published findings on the ongoing smishing campaign linked to the Smishing Triad, detailing the kit's functionalities.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track Noodle RAT and Shopify in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed