W3LL phishing kit is a phishing kit sold for approximately $500 that enabled cybercriminals to create convincing fake or replica login pages for credential theft. Investigators described it as part of a broader full-service cybercrime platform associated with W3LLSTORE, an online marketplace used to buy and sell stolen credentials and which facilitated the sale of more than 25,000 compromised accounts between 2019 and 2023. After W3LLSTORE shut down in 2023, the operation reportedly continued privately through encrypted messaging platforms and was rebranded for private distribution.
From 2023 to 2024, the kit was used in more than 17,000 attacks worldwide. Group-IB linked it to phishing campaigns targeting corporate environments, including Microsoft 365 accounts, and reported that attackers using the platform attempted to bypass authentication protections and gain persistent access. The United States accounted for 56.9% of identified cases, followed by the United Kingdom at 6.9%, Australia at 4.6%, Germany at 2.6%, Canada and France at 2.1% each, the Netherlands at 2.0%, Switzerland at 1.8%, and Italy at 1.6%. Manufacturing, technology, and professional services were among the most affected sectors.
The phishing operation built around the kit was tied by investigators to more than $20 million in attempted fraud. A joint action by the FBI Atlanta Field Office and the Indonesian National Police seized infrastructure and domains tied to the operation and detained an alleged developer identified as G.L. Authorities stated the operation enabled the theft of thousands of victims’ account credentials and that the takedown targeted both users of the phishing tooling and the developers supplying it.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Once a victim entered their details, the tool captured both login credentials and session data, allowing attackers to bypass MFA and retain access to the account.
Once a victim entered their details, the tool captured both login credentials and session data, allowing attackers to bypass MFA and retain access to the account.
It actively captured session cookies and authentication tokens. This technique allowed the attackers to bypass multi-factor authentication protocols seamlessly and establish persistent, unauthorized access to the compromised accounts...
This kit was part of a larger cybercrime platform that included W3LLSTORE, an online marketplace facilitating the sale of over 25,000 compromised accounts between 2019 and 2023.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing kit used to create convincing fake login pages for credential theft, specifically usernames and passwords.
A phishing kit used to create convincing fake login pages and steal usernames and passwords from victims. It was sold as part of a broader cybercrime platform and used in large-scale campaigns targeting corporate accounts, including Microsoft 365, with attempts to bypass authentication protections and gain persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.