W3LL Phishing-as-a-Service Ecosystem Dismantled — FBI/Indonesia Takedown of $20M BEC Platform — Threadlinqs Intelligence
As of 2026-05-30, W3LL Phishing-as-a-Service Ecosystem Dismantled — FBI/Indonesia Takedown of $20M BEC Platform is a high-severity phishing threat attributed to W3LL (Indonesia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0373 · Severity: HIGH · Status: MONITORING · Category: PHISHING
Attribution: W3LL · Indonesia · FINANCIAL
The FBI and Indonesian National Police dismantled the W3LL phishing-as-a-service ecosystem, a 7-year criminal enterprise that sold a $500 AiTM phishing kit enabling 500+ cybercriminals to bypass MFA
W3LL was a sophisticated phishing-as-a-service (PhaaS) platform that operated from approximately 2017 through its takedown in April 2026. The ecosystem centered on the W3LL Panel OV6 — a fully automated adversary-in-the-middle (AiTM) phishing kit specifically designed to bypass multi-factor authentication on Microsoft 365 corporate accounts by intercepting session cookies during the authentication process.
The W3LL Store, an underground marketplace that operated from 2018 to 2023, served as the primary distribution channel. It sold the W3LL Panel kit for $500 per 3-month license ($150/month renewal) alongside 16+ additional tools covering the full BEC kill chain: OKELO (vulnerability scanner), CONTOOL (automated account discovery with email monitoring and Telegram notifications), W3LL Sender and PunnySender (SMTP bulk email tools), W3LL Redirect (malicious link staging), and LOMPAT (email validation). Revenue exceeded $500,000 between October 2022 and July 2023 alone, with 3,800+ items sold.
The AiTM attack chain operated by proxying the legitimate Microsoft 365 login portal through the W3LL Panel infrastructure. When victims clicked phishing links — typically disguised as Adobe Shared File pages (wfiles.html) — their browser communicated with the W3LL proxy server rather than directly with Microsoft. The kit intercepted credentials, one-time MFA passcodes, and most critically, authentication session cookies. These stolen session cookies allowed attackers to bypass MFA entirely, hijacking authenticated sessions without needing to re-authenticate. Anti-detection mechanisms included IonCube PHP encryption/obfuscation, Punycode encoding in email headers, HTML tag obfuscation, and multi-layer JavaScript encoding (base64) that loaded scripts directly from W3LL Panel infrastructure.
The infrastructure was identifiable by its characteristic /OV6 control panel path, heavily obfuscated PHP files, and credential exfiltration through wazzy.php endpoints. Stolen credentials were transmitted via Hastebin (file-sharing), Telegram bots, and email. The kit used valid Let's Encrypt TLS certificates to appear legitimate.
After the W3LL Store shut down in 2023, the operation continued through encrypted messaging platforms including Telegram, where the toolkit was rebranded and sold to new operators. The developer also secretly collected and resold access to compromised accounts — a double monetization scheme.
Code from W3LL OV6 was subsequently reused in the Sneaky 2FA phishing kit, identified by Sekoia in December 2024/January 2025, demonstrating the persistent influence of W3LL's codebase in the PhaaS ecosystem even after the marketplace closure.
The FBI Atlanta Field Office, in coordination with the Indonesian National Police, executed the takedown on April 13, 2026 — seizing infrastructure, key domains including w3ll.store, and arresting the alleged developer identified as 'G.L.' in Indonesia. Federal charges include conspiracy to commit wire fraud, computer fraud and abuse violations, and money laundering, carrying up to 20 years in federal prison. This represents the first coordinated US-Indonesia enforcement action against a phishing kit developer.
Weaknesses (CWE)
CWE-294, CWE-384, CWE-522
Target sectors: manufacturing, information-technology, financial-services, healthcare, legal, government, education, energy, retail, telecommunications
Target regions: North America, Europe, Asia-Pacific, Middle East, Global
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1566, T1566, T1204, T1204, T1078, T1098, T1114, T1027, T1027, T1036