JWR is a phishing framework built for live fraud. It turns a fake payment or bank page into a live channel that lets criminals watch details arrive as they are typed.
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
JWR in ATT&CK
17 distinct techniquesTechniques
17 techniques T1056 Input Capture T1041 Exfiltration Over C2 Channel T1573 Encrypted Channel T1071 Application Layer Protocol T1036 Masquerading T1566 Phishing T1027 Obfuscated Files or Information T1071.001 Web Protocols T1497.001 System Checks T1566.003 Spearphishing via Service T1592 Gather Victim Host Information T1539 Steal Web Session Cookie T1059.007 JavaScript T1614 System Location Discovery T1008 Fallback Channels T1622 Debugger Evasion T1082 System Information Discovery