securityonline.info 8/20/2026, 8:11:03 AM · external

Chinese linked JWR phishing kit targets Shopify, PayPal via SMS

Chinese linked JWR phishing kit targets Shopify, PayPal via SMS
CyberSIXT Evidence Panel

CISCO Talos has identified a new phishing framework called JWR, operated by suspected Chinese-speaking cybercriminals. This tool, labeled as "Phishing-as-a-Service (PhaaS)", allows real-time monitoring of victims through deceptive login pages targeting payment platforms like Shopify and PayPal. The malware employs widespread SMS phishing campaigns, exploiting multiple methods to extract sensitive information beyond payment details, such as identity documents and 2FA codes.

Its architecture supports three communication modes and uses AES-CTR encryption to secure stolen data. Current law enforcement efforts, including the FBI's Operation Ghost Hook, seek to disrupt these activities, but the potential for identity theft remains high. Users are urged to exercise caution with unsolicited messages and adopt security measures to protect themselves.

View Primary Source Via securityonline.info

Article by CyberSIXT