TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #993 650
🚨 Inside the Smishing Triad’s Phishing Cockpit

Group-IB’s latest research dives into JWR, a phishing kit used by the Outsider cluster, revealing how attackers turn phishing pages into real-time fraud operations.

Key findings:
🔹32 operator commands for real-time victim manipulation
🔹Keystroke-level credential and payment-data capture
🔹~70 data fields for PII, cards, OTPs, credentials and device data
🔹WebSocket C2 with AES-256-CTR encrypted communications
🔹Distinctive fingerprints, IOCs, YARA and Suricata detection rules

Read the full technical analysis.

#Phishing #Smishing #CyberCrime
  • 🔥 10
  • 👍 3
  • 😍 3
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  4. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  5. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
  6. Aug 27, 2026🚨 By the time a bank detects fraud, legacy systems are simply watching the end of a story…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →