The FBI Atlanta Field Office and the Indonesian National Police dismantled infrastructure tied to the W3LL phishing operation, seized associated domains, and detained an alleged developer identified as G.L. Authorities said the platform enabled more than $20 million in attempted fraud by selling a low-cost phishing kit and operating W3LLSTORE, a marketplace that trafficked stolen credentials and unauthorized access. Investigators said the service sold kits for about $500, supported roughly 500 threat actors, and facilitated the sale of more than 25,000 compromised accounts between 2019 and 2023.
Researchers and law enforcement described W3LL as a full-service phishing and business email compromise platform used in more than 17,000 attacks worldwide from 2023 to 2024, with the United States accounting for more than half of identified cases. Group-IB, Hunt.io, and Sekoia linked the operation to Microsoft 365-focused adversary-in-the-middle phishing, session cookie theft, MFA bypass, and code reuse in other kits such as Sneaky 2FA. Authorities said the operation continued on encrypted messaging platforms after W3LLSTORE shut down in 2023, underscoring how commercial phishing services lowered the barrier for attacks against sectors including manufacturing, technology, and professional services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The FBI said the W3LL takedown marked the first coordinated enforcement action between the United States and Indonesia against a phishing kit developer. The announcement framed the seizure of infrastructure and detention of alleged developer G.L. as a milestone in bilateral cybercrime cooperation.
As part of the takedown, Indonesian authorities detained an alleged developer of the W3LL platform identified as G.L. Officials said the action was intended to disrupt both the users of the phishing kit and the developers supplying it.
The FBI Atlanta Field Office and the Indonesian National Police disrupted the W3LL phishing operation by seizing infrastructure and domains tied to the scheme. Authorities said the network was linked to more than $20 million in attempted fraud.
Security firms including Group-IB, Hunt.io, and Sekoia publicly connected W3LL to adversary-in-the-middle phishing, session cookie theft, MFA bypass, and code reuse in other kits such as Sneaky 2FA. These findings expanded understanding of the toolkit's technical capabilities and ecosystem.
From 2023 to 2024, the W3LL phishing kit was used in more than 17,000 attacks globally. Group-IB linked the activity to campaigns targeting corporate environments, especially Microsoft 365 accounts, with the United States accounting for more than half of identified cases.
Between 2019 and 2023, W3LLSTORE enabled the sale of more than 25,000 compromised accounts. Researchers said the platform served roughly 500 threat actors and helped scale credential theft and business email compromise activity.
In 2023, the W3LLSTORE marketplace ceased operating. Authorities said the broader phishing operation did not end and instead shifted to encrypted messaging platforms.
By 2019, the W3LL operation was active as a full-service cybercrime platform, selling a phishing kit for about $500 and offering related services through the W3LLSTORE marketplace. The marketplace supported trafficking in stolen credentials, compromised servers, mailing lists, and unauthorized system access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceinfosec.pub
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.