Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

W3LL Phishing Kit Launches Active Campaign to Steal Outlook Login Credentials

Cybersecurity researchers have identified a sophisticated phishing campaign utilizing the W3LL Phishing Kit.

Cybersecurity researchers have identified a sophisticated phishing campaign utilizing the W3LL Phishing Kit.

First identified by Group-IB in 2022, W3LL operates as a phishing-as-a-service (PaaS) tool, facilitated by a marketplace called the W3LL Store. This platform allows threat actors to purchase specific functionalities and components for tailored phishing campaigns, offering more flexibility than conventional kits.

Advanced Phishing-as-a-Service Campaign

The campaign primarily targets Microsoft 365, specifically Outlook login credentials, employing adversary-in-the-middle (AitM) techniques. These methods enable attackers to intercept session cookies, bypassing multi-factor authentication protections.

Researchers from Hunt discovered a phishing campaign using a webpage impersonating Adobe’s Shared File service. Victims are prompted to enter their Outlook credentials to access a purported document. Although the page lacks personalization, it effectively uses social engineering to exploit trust in well-known brands.

An open directory associated with the campaign showed folders labeled “OV6,” indicating the use of the W3LL kit. The kit includes obfuscated PHP files managing credential harvesting, using encryption tools like IonCube to hinder reverse engineering.

Credentials entered into the fake login page are sent to a remote script, wazzy.php , hosted on teffcopipe[.]com, likely for processing and storing stolen data. The kit’s “OV6_ENCODED” directory contains configuration files like “config.php,” highlighting its modularity and scalability.

Cybersecurity researchers have identified a sophisticated phishing campaign utilizing the W3LL Phishing Kit.
نضال النعيم · Thehackingpost

The infrastructure utilizes a Let’s Encrypt certificate, potentially bypassing basic browser security warnings. The W3LL kit poses significant risks by offering cybercriminals comprehensive tools to bypass MFA and automate credential theft.

Organizations are advised to maintain awareness of emerging phishing campaigns and invest in employee training on phishing recognition. Security professionals should leverage tools like Hunt’s open directory crawler for early detection of exposed directories.

Type Indicator Notes

Open Directory 192.3.137[.]252:443 Likely hosts kit components

Advertisement

C2 Infrastructure teffcopipe[.]com Receives POST credential data

C2 IP 5.63.8[.]243 Associated with phish backend

Malicious Script /wazzy.php Credential collection endpoint

Certificate Let’s Encrypt Valid: 2023-12-20 to 2024-03-19

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories