W3LL Phishing-as-a-Service Ecosystem Dismantled — FBI/Indonesia Takedown of $20M BEC Platform

W3LL Phishing-as-a-Service Ecosystem Dismantled (TL-2026-0373), also tracked as W3LL Panel OV6, is a high-severity phishing campaign, first published 2026-04-16. It is attributed to W3LL (Indonesia) with high confidence, affects Microsoft Microsoft 365, maps to 19 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-0373

Threat ID
TL-2026-0373
Also known as
W3LL Panel OV6, W3LL Store, W3LL Done, Operation W3LL
Severity
HIGH
Status
MONITORING
Category
PHISHING
First published
2026-04-16
Last reviewed
2026-04-16
Attribution
W3LL
Attribution confidence
HIGH
Nation-state nexus
Indonesia
Motivation
FINANCIAL
Target sectors
manufacturing, information-technology, financial-services, healthcare, legal, government, education, energy, retail, telecommunications
Target regions
North America, Europe, Asia-Pacific, Middle East, Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in W3LL Phishing-as-a-Service Ecosystem Dismantled

Malware and tooling: CONTOOL, LOMPAT, OKELO, PunnySender, W3LL Panel, W3LL Panel OV6, W3LL Redirect

The FBI and Indonesian National Police dismantled the W3LL phishing-as-a-service ecosystem, a 7-year criminal enterprise that sold a $500 AiTM phishing kit enabling 500+ cybercriminals to bypass MFA and compromise 25,000+ Microsoft 365 accounts, facilitating over $20 million in fraud attempts. The alleged developer 'G.L.' was arrested in Indonesia in the first coordinated US-Indonesia enforcement action against a phishing kit developer.

How W3LL Phishing-as-a-Service Ecosystem Dismantled works

W3LL was a sophisticated phishing-as-a-service (PhaaS) platform that operated from approximately 2017 through its takedown in April 2026. The ecosystem centered on the W3LL Panel OV6 — a fully automated adversary-in-the-middle (AiTM) phishing kit specifically designed to bypass multi-factor authentication on Microsoft 365 corporate accounts by intercepting session cookies during the authentication process.

The W3LL Store, an underground marketplace that operated from 2018 to 2023, served as the primary distribution channel. It sold the W3LL Panel kit for $500 per 3-month license ($150/month renewal) alongside 16+ additional tools covering the full BEC kill chain: OKELO (vulnerability scanner), CONTOOL (automated account discovery with email monitoring and Telegram notifications), W3LL Sender and PunnySender (SMTP bulk email tools), W3LL Redirect (malicious link staging), and LOMPAT (email validation). Revenue exceeded $500,000 between October 2022 and July 2023 alone, with 3,800+ items sold.

The AiTM attack chain operated by proxying the legitimate Microsoft 365 login portal through the W3LL Panel infrastructure. When victims clicked phishing links — typically disguised as Adobe Shared File pages (wfiles.html) — their browser communicated with the W3LL proxy server rather than directly with Microsoft. The kit intercepted credentials, one-time MFA passcodes, and most critically, authentication session cookies. These stolen session cookies allowed attackers to bypass MFA entirely, hijacking authenticated sessions without needing to re-authenticate. Anti-detection mechanisms included IonCube PHP encryption/obfuscation, Punycode encoding in email headers, HTML tag obfuscation, and multi-layer JavaScript encoding (base64) that loaded scripts directly from W3LL Panel infrastructure.

The infrastructure was identifiable by its characteristic /OV6 control panel path, heavily obfuscated PHP files, and credential exfiltration through wazzy.php endpoints. Stolen credentials were transmitted via Hastebin (file-sharing), Telegram bots, and email. The kit used valid Let's Encrypt TLS certificates to appear legitimate.

After the W3LL Store shut down in 2023, the operation continued through encrypted messaging platforms including Telegram, where the toolkit was rebranded and sold to new operators. The developer also secretly collected and resold access to compromised accounts — a double monetization scheme.

Code from W3LL OV6 was subsequently reused in the Sneaky 2FA phishing kit, identified by Sekoia in December 2024/January 2025, demonstrating the persistent influence of W3LL's codebase in the PhaaS ecosystem even after the marketplace closure.

The FBI Atlanta Field Office, in coordination with the Indonesian National Police, executed the takedown on April 13, 2026 — seizing infrastructure, key domains including w3ll.store, and arresting the alleged developer identified as 'G.L.' in Indonesia. Federal charges include conspiracy to commit wire fraud, computer fraud and abuse violations, and money laundering, carrying up to 20 years in federal prison. This represents the first coordinated US-Indonesia enforcement action against a phishing kit developer.

MITRE ATT&CK techniques used in TL-2026-0373

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Persistence

T1078 Valid Accounts; T1098 Account Manipulation

collection

T1114 Email Collection

Execution

T1204 User Execution

Lateral Movement

T1534 Internal Spearphishing

Initial Access

T1566 Phishing

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

Impact

T1657 Financial Theft

Affected products and versions in W3LL Phishing-as-a-Service Ecosystem Dismantled

  • Microsoft — Microsoft 365
    Vulnerable versions: All versions with session-based authentication
    Fixed in: N/A — requires phishing-resistant MFA deployment
  • Microsoft — Outlook Web Access
    Vulnerable versions: All versions
    Fixed in: N/A — requires phishing-resistant MFA
  • Microsoft — Azure Active Directory
    Vulnerable versions: All versions using session cookies without token binding
    Fixed in: Token protection (preview) mitigates session theft

Remediation for W3LL Phishing-as-a-Service Ecosystem Dismantled

Immediate actions

  • Block known W3LL infrastructure IPs (192.3.137.252, 5.63.8.243, 23.106.122.155) at perimeter firewalls
  • Block teffcopipe.com and w3ll.store domains at DNS/proxy level
  • Audit Microsoft 365 sign-in logs for anomalous session token reuse from unfamiliar IPs
  • Force re-authentication for all Microsoft 365 sessions with suspicious token activity
  • Review email transport rules for unauthorized forwarding rules (common BEC persistence)
  • Check Hastebin and Telegram-based data exfiltration in proxy/firewall logs

Workarounds

  • Restrict legacy authentication protocols that bypass modern MFA
  • Enable sign-in risk policies in Azure AD Identity Protection
  • Configure session lifetime limits to reduce session cookie replay window

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) to eliminate AiTM session cookie theft
  • Implement Conditional Access policies requiring compliant devices and trusted locations
  • Enable Microsoft 365 token protection (token binding) to prevent stolen session cookie replay
  • Deploy email authentication (DMARC enforcement, DKIM, SPF) to reduce spoofed phishing emails
  • Implement real-time phishing URL detection at email gateway and web proxy layers
  • Monitor for /OV6 path patterns in web proxy logs as W3LL kit deployment indicator
  • Conduct BEC awareness training focused on AiTM session hijacking risks

Weaknesses (CWE) in W3LL Phishing-as-a-Service Ecosystem Dismantled

CWE-294, CWE-384, CWE-522

Timeline of W3LL Phishing-as-a-Service Ecosystem Dismantled

  • W3LL operator believed to have begun developing phishing tools and building the criminal ecosystem
  • W3LL Store underground marketplace launches, offering phishing kits, compromised credentials, web shells, VPN/RDP access, and custom tools to cybercriminal customers
  • W3LL Store begins facilitating large-scale credential sales; between 2019-2023, over 25,000 compromised Microsoft 365 accounts sold through the marketplace
  • Peak operational period begins — W3LL Store generates $500,000+ in revenue between October 2022 and July 2023, selling 3,800+ items to 500+ cybercriminal customers
  • Group-IB publishes 'W3LL Done' report exposing the W3LL phishing ecosystem, documenting 850+ phishing campaigns targeting 56,000+ Microsoft 365 accounts with 8,000+ confirmed compromises
  • W3LL Store marketplace shuts down following Group-IB exposure; operations migrate to encrypted messaging platforms including Telegram where toolkit is rebranded and sold
  • Let's Encrypt TLS certificate issued for active W3LL phishing infrastructure at 192.3.137.252, used to host OV6 panel components and credential harvesting pages
  • Hunt.io publishes analysis of active W3LL campaigns targeting Outlook credentials via spoofed Adobe Shared File pages, identifying open directory at 192.3.137.252 and C2 at teffcopipe.com
  • Sekoia identifies Sneaky 2FA phishing kit reusing source code from W3LL Panel OV6, demonstrating the persistent influence of W3LL codebase in the PhaaS ecosystem even after marketplace closure
  • Federal charges filed against W3LL developer under conspiracy to commit wire fraud, Computer Fraud and Abuse Act violations, and money laundering statutes, carrying up to 20 years in federal prison
  • FBI Atlanta Field Office and Indonesian National Police execute coordinated takedown — seizing W3LL infrastructure and key domains, arresting alleged developer 'G.L.' in Indonesia in first-ever US-Indonesia enforcement action against a phishing kit developer
  • As of 2026-05-29, the W3LL operation is contained: the FBI/Indonesian Police takedown (Apr 13, 2026) seized domains and arrested developer 'G.L.', confirmed by the FBI and multiple outlets. But its OV6 codebase persists in Sneaky 2FA/Sneaky Log and the AiTM M365 technique remains widely exploited, so the threat lineage warrants monitoring.

Sources cited for W3LL Phishing-as-a-Service Ecosystem Dismantled

Threats related to W3LL Phishing-as-a-Service Ecosystem Dismantled

Detection coverage for TL-2026-0373

As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0373 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats