W3LL Phishing Kit Launches Active Campaign to Steal Outlook Login Credentials
Cybersecurity researchers have identified a sophisticated phishing campaign utilizing the W3LL Phishing Kit.
Cybersecurity researchers have identified a sophisticated phishing campaign utilizing the W3LL Phishing Kit.
First identified by Group-IB in 2022, W3LL operates as a phishing-as-a-service (PaaS) tool, facilitated by a marketplace called the W3LL Store. This platform allows threat actors to purchase specific functionalities and components for tailored phishing campaigns, offering more flexibility than conventional kits.
Advanced Phishing-as-a-Service Campaign
The campaign primarily targets Microsoft 365, specifically Outlook login credentials, employing adversary-in-the-middle (AitM) techniques. These methods enable attackers to intercept session cookies, bypassing multi-factor authentication protections.
Researchers from Hunt discovered a phishing campaign using a webpage impersonating Adobe’s Shared File service. Victims are prompted to enter their Outlook credentials to access a purported document. Although the page lacks personalization, it effectively uses social engineering to exploit trust in well-known brands.
An open directory associated with the campaign showed folders labeled “OV6,” indicating the use of the W3LL kit. The kit includes obfuscated PHP files managing credential harvesting, using encryption tools like IonCube to hinder reverse engineering.
Credentials entered into the fake login page are sent to a remote script, wazzy.php , hosted on teffcopipe[.]com, likely for processing and storing stolen data. The kit’s “OV6_ENCODED” directory contains configuration files like “config.php,” highlighting its modularity and scalability.
Cybersecurity researchers have identified a sophisticated phishing campaign utilizing the W3LL Phishing Kit.
The infrastructure utilizes a Let’s Encrypt certificate, potentially bypassing basic browser security warnings. The W3LL kit poses significant risks by offering cybercriminals comprehensive tools to bypass MFA and automate credential theft.
Organizations are advised to maintain awareness of emerging phishing campaigns and invest in employee training on phishing recognition. Security professionals should leverage tools like Hunt’s open directory crawler for early detection of exposed directories.
Type Indicator Notes
Open Directory 192.3.137[.]252:443 Likely hosts kit components
C2 Infrastructure teffcopipe[.]com Receives POST credential data
C2 IP 5.63.8[.]243 Associated with phish backend
Malicious Script /wazzy.php Credential collection endpoint
Certificate Let’s Encrypt Valid: 2023-12-20 to 2024-03-19
Based on reporting by GBHackers.
