THE ESSENTIALS
  • Operators can alter the credential-capture sequence during a live victim session.

What changed

Group-IB published a September 14 technical analysis of the JWR phishing kit used by a cluster it tracks as Outsider. Researchers examined recovered browser code, a communications worker and an encrypted configuration response. They report that operators receive keystrokes and can switch victims between credential, card and one-time-password capture screens while a session is underway.

Why it matters

The findings give defenders concrete behaviour to investigate beyond a suspicious landing-page address. Group-IB describes encrypted WebSocket traffic with an HTTP fallback, helping explain how the fraudulent pages maintain contact with their operators.

What remains unproven

This is an analysis of particular recovered artefacts, not a census of the wider Smishing Triad ecosystem. Attribution remains Group-IB’s assessment; the report does not establish losses caused by this specific deployment.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. Group-IB ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗