{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/klarna/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Shopify Checkout","PayPal Login","Apple Login","Klarna Checkout"],"_cs_severities":["high"],"_cs_tags":["phishing","credential-theft","websocket","saas"],"_cs_type":"advisory","_cs_vendors":["Shopify","PayPal","Apple","Klarna"],"content_html":"\u003cp\u003eCisco Talos has identified an undocumented phishing framework, referred to as \u0026quot;JWR,\u0026quot; which facilitates highly interactive, operator-steered credential and data theft. Unlike static phishing kits, JWR utilizes a dual-mode client engine - Host Bridge and Content Mode - to maintain a persistent, AES-CTR encrypted WebSocket connection to a C2 server. This allows attackers to monitor victims in real-time, stream keystrokes, and issue over 40 distinct instructions to steer the victim through 44 different phishing page flows. The framework captures comprehensive data, including full payment card details, Social Security numbers, passport/ID images, 2FA codes, and device fingerprints. Evidence suggests JWR may be a variant of \u0026quot;The Outsider\u0026quot; phishing-as-a-service platform. Campaigns have been observed using SMS-based lures impersonating postal and toll authorities in Southeast Asia and the Middle East, targeting users of major platforms like Shopify, PayPal, Apple, and Klarna.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends SMS lures impersonating legitimate postal, courier, or toll authorities to victims.\u003c/li\u003e\n\u003cli\u003eVictim clicks the link, loading a phishing page that initiates the JWR client-side engine.\u003c/li\u003e\n\u003cli\u003eThe client engine checks the global flag 'window.__HOST_MODE' to determine the execution path (Host Bridge or Content Mode).\u003c/li\u003e\n\u003cli\u003eThe Host Bridge IIFE establishes a persistent WebSocket connection to the attacker's C2 server at the path 'webSocket/QT/{sessionId}/'.\u003c/li\u003e\n\u003cli\u003eThe client spawns a Web Worker ('static/js/ws-worker.js') to maintain the C2 connection independently of page navigation.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the C2 console to issue real-time instructions, such as redirecting the victim or updating the phishing page state.\u003c/li\u003e\n\u003cli\u003eThe client engine streams the victim's keystrokes and input data (PII, credentials, payment data) back to the C2 server in JSON format.\u003c/li\u003e\n\u003cli\u003eUpon session closure, the final data payload is encrypted via the 'JwrCrypto' module and transmitted to the attacker's server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe JWR framework facilitates high-fidelity identity and financial theft. By leveraging real-time operator control, the attackers can bypass standard MFA by prompting for codes during the interactive session. The impact includes financial fraud, full identity theft via PII/ID documentation exfiltration, and potential secondary account takeovers using harvested session credentials. While specific victim counts are not provided, the scope spans multiple international regions and major global financial/shopping brands.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock known malicious SMS delivery infrastructure and egress traffic to identified phishing kit C2 domains.\u003c/li\u003e\n\u003cli\u003eImplement SMS filtering solutions that identify and flag phishing-related URLs commonly used in courier or toll authority impersonation scams.\u003c/li\u003e\n\u003cli\u003eDeploy web proxy or DNS-level filtering to alert on requests for 'static/js/ws-worker.js' in contexts associated with suspicious domains.\u003c/li\u003e\n\u003cli\u003eEducate users on the risks of interacting with unsolicited SMS messages, particularly those requesting credentials or payment to resolve postal or toll issues.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T10:37:11Z","date_published":"2026-08-13T10:37:11Z","id":"https://feed.craftedsignal.io/briefs/2026-08-jwr-phishing/","summary":"The JWR phishing framework is a sophisticated, operator-steered PhaaS platform that uses persistent WebSocket connections to capture PII, payment credentials, and device fingerprints in real-time.","title":"JWR Phishing Framework Analysis","url":"https://feed.craftedsignal.io/briefs/2026-08-jwr-phishing/"}],"language":"en","title":"CraftedSignal Threat Feed - Klarna","version":"https://jsonfeed.org/version/1.1"}