JWR phishing kit steals bank accounts in real time
JWR is a phishing kit that steals bank account details and lets attackers empty accounts in real time. Attackers use it to trick users into entering their online banking credentials on fake sites.
- Report priority
- Medium
How it works
- Attackers send fake emails or messages with links to lookalike bank websites.
- When users log in, JWR steals their credentials and lets attackers transfer money from their accounts immediately.
What to do
If you clicked a link in a suspicious email or message pretending to be from your bank and entered your login details on a fake site, never enter bank login details on anythe normal update channel or app for updates, and report phishing attempts to your bank immediately.
Technical details
An attacker sends you an email pretending to be from your bank. It says your account needs updating. You click the link and land on a fake login page that looks real. When you enter your username and password, the attacker sees them instantly and starts moving money out of your account while you're still on the page.
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation.