A newly discovered phishing framework called the JWR phishing kit gives criminals real-time visibility into the information victims type into fake websites. The tool can mimic payment, login and checkout pages for brands including PayPal, Apple, Shopify, WooCommerce, Klarna and banks.
Unlike many phishing pages, JWR does not wait for a victim to submit a form. Attackers can watch card numbers, passwords and verification codes appear as the victim types them.
Cisco Talos researchers found that the framework gives operators extensive control over the fake page. They can change messages, request more information and direct victims through additional verification steps while the scam is still underway.
Attackers see information before victims submit forms
The JWR phishing kit maintains a live connection between the victim’s browser and the attacker’s command-and-control infrastructure. It uses an AES-CTR-encrypted WebSocket channel, allowing operators to receive entered information immediately.
This gives criminals time to react to each victim. For example, an operator can show a fake card-declined message after receiving payment details. The victim may then enter a different card, providing the attacker with even more financial information.
If the operator accepts the entered card details, the page can move the victim to a fake identity-verification screen. The scam then requests a one-time code, which may give attackers the final detail needed to access an account or complete fraudulent payments.
After collecting the information, the fake site can redirect the victim to the legitimate website. That step can make the scam less obvious and leave victims unaware that they exposed sensitive data.
Fake checkout pages can copy real carts
JWR includes dedicated support for Shopify and WooCommerce. These integrations can rebuild a victim’s shopping cart on a fraudulent checkout page using the cart data from the original store.
As a result, victims may see the real items they intended to buy, making the fake checkout look highly convincing. The framework can imitate not only payment forms but also the flow and context of a legitimate purchase.
Talos identified 44 phishing pages and more than 40 different commands issued from the framework’s command-and-control console.
Framework targets payments, credentials and identity data
The JWR phishing kit targets far more than payment card details. Researchers said it can collect website credentials, PayPal logins, two-factor authentication codes and complete device fingerprints.
The framework can also request identity documents, Social Security numbers, passport images and driver’s licence images. Such data can support account takeover, identity fraud and follow-up social engineering attacks.
Talos observed JWR in SMS phishing campaigns that impersonated toll services, road-pricing systems, postal firms and courier companies. The campaigns targeted people in Southeast Asia and the Middle East through malicious links delivered by text message.
Researchers link JWR to Outsider phishing service
The JWR operator interface contains Simplified Chinese, which suggests a Chinese-speaking actor operated the observed campaign.
Talos assessed with medium confidence that JWR is a variant of the Outsider phishing-as-a-service platform. Researchers based the assessment on similarities in the framework’s client-side scripts and functions.
Outsider has operated since 2023 and has been linked to an estimated $1.9 billion in losses across 55 countries. The FBI announced an operation against the service in June 2026, but Talos warned that earlier self-service sales may have allowed variants to continue circulating.
Conclusion
The JWR phishing kit makes online scams more dangerous by giving attackers live control over the victim’s experience. Users should avoid opening unexpected links in SMS messages and should enter payment or login details only after independently opening the official website.


0 responses to “JWR phishing kit mimics PayPal, Apple and online stores”