Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit (opens in a new tab)
Why readTeardown of the Smishing Triad's JWR phishing kit: AES-256-CTR over WebSocket for exfil, real-time operator control of victim sessions, and indicators tied to the Outsider cluster.
The JWR kit walks SMS-lured victims through a staged capture funnel (identity, card, OTP, sometimes a second bank or wallet) while a human operator watches the session live and pushes control instructions. Communications run over encrypted WebSockets using AES-256-CTR, with short-link redirection into disposable apex domains hosting the kit. Group-IB names the Outsider operator cluster and publishes infrastructure detail and indicators; the real-time operator handoff is the part detection built around static landing pages will miss.