Researchers at Cisco Talos have detailed a new and highly sophisticated phishing framework known as "JWR". This framework moves beyond traditional, static phishing kits by enabling live, interactive attacks steered by a human operator. Through an encrypted WebSocket connection, attackers can monitor victims in real-time, guiding them through fake login and checkout processes to steal a wide range of sensitive data, including credentials, 2FA codes, payment information, and personal documents. The framework is being actively used in smishing campaigns and is assessed to be a variant of another Phishing-as-a-Service (PhaaS) platform called "The Outsider," with potential links to Chinese-speaking actors. The rise of such interactive frameworks poses a significant threat as they are designed to defeat common security controls like multi-factor authentication.
JWR represents the next evolution in phishing, often referred to as Adversary-in-the-Middle (AiTM) phishing. Instead of just hosting a fake page and waiting for credentials, the framework acts as a real-time proxy and interactive console for the attacker.
How it works:
This live interaction allows the attacker to adapt to unexpected user behavior and overcome challenges that would foil an automated kit, making it highly effective at bypassing MFA.
The core of the JWR framework is its use of WebSockets for persistent, bidirectional communication. This is a significant step up from the simple POST requests used by most phishing kits. The communication is encrypted using AES-CTR, making it difficult for network security tools to inspect the exfiltrated data.
The framework is designed to be modular and can convincingly impersonate a wide variety of major brands, including Shopify, PayPal, Apple, and Klarna.
MITRE ATT&CK techniques associated with this activity include:
Cisco Talos assesses with medium confidence that JWR is related to "The Outsider" PhaaS platform and may be operated by Chinese-speaking actors, based on code similarities and language artifacts in the operator console.
The impact of a successful JWR attack is far greater than a standard phishing attack. Because it can defeat MFA, it can lead to the full compromise of highly sensitive accounts (e.g., email, banking, corporate SSO). The ability to steal identity documents also opens the door to identity theft and the creation of fraudulent accounts in the victim's name. For organizations, the compromise of a single employee's account via JWR could provide an initial access vector for a major network intrusion. The campaigns have been observed targeting users in Southeast Asia and the Middle East.
No specific domains, IPs, or file hashes were provided in the source articles.
Detecting this activity is challenging due to its proxying nature and encryption. However, security teams can look for:
WebSocket Connectionswss://) connections to new or uncategorized domains from user workstations could be suspicious.Unusual SSL CertificatesLures in SMS/EmailImplement phishing-resistant MFA such as FIDO2/WebAuthn, which is not susceptible to AiTM attacks.
Mapped D3FEND Techniques:
Train users to identify and report smishing and phishing attempts, and to be cautious of unexpected requests for credentials or personal information.
Use web filtering and email security gateways to block access to known and suspected phishing domains.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.