- Operators can alter the credential-capture sequence during a live victim session.
What changed
Group-IB published a September 14 technical analysis of the JWR phishing kit used by a cluster it tracks as Outsider. Researchers examined recovered browser code, a communications worker and an encrypted configuration response. They report that operators receive keystrokes and can switch victims between credential, card and one-time-password capture screens while a session is underway.
Why it matters
The findings give defenders concrete behaviour to investigate beyond a suspicious landing-page address. Group-IB describes encrypted WebSocket traffic with an HTTP fallback, helping explain how the fraudulent pages maintain contact with their operators.
What remains unproven
This is an analysis of particular recovered artefacts, not a census of the wider Smishing Triad ecosystem. Attribution remains Group-IB’s assessment; the report does not establish losses caused by this specific deployment.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
