{"id":4072,"date":"2025-05-20T10:03:46","date_gmt":"2025-05-20T10:03:46","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/20\/w3ll-phishing-kit-actively-attacking-users-to-steal-outlook-login-credentials\/"},"modified":"2025-05-20T10:03:46","modified_gmt":"2025-05-20T10:03:46","slug":"w3ll-phishing-kit-actively-attacking-users-to-steal-outlook-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/20\/w3ll-phishing-kit-actively-attacking-users-to-steal-outlook-login-credentials\/","title":{"rendered":"W3LL Phishing Kit Actively Attacking Users to Steal Outlook Login Credentials"},"content":{"rendered":"<p>    W3LL Phishing Kit Actively Attacking Users to Steal Outlook Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated phishing campaign utilizing the W3LL Phishing Kit has been actively targeting users\u2019 Microsoft Outlook credentials through elaborate impersonation techniques.<\/p>\n<p>First identified by Group-IB in 2022, this phishing-as-a-service (PhaaS) tool has evolved into a comprehensive ecosystem complete with its own marketplace called W3LL Store, where malicious actors can customize campaign capabilities according to their specific needs.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrSnpj8OLStkc0-rnXdVf_lAWvXFLWO2nJ1slXg9tDSiFiiBYIInIIlHKyHMufTdRWlK2xdAV7G4otZbt_dX_zeSG_hZAOlXAN9BsZJ1YPB3NKiL6BlsUy7Ih7CbvmH6vN1ZgexvriX9ndqyVoO0c3x7wwrR2spjwOFLqk-ufJZGJmM8GCpqoc2n5shyphenhypheng\/s16000\/W3LL%2520Phishing%2520Kit%2520Files%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">W3LL Phishing Kit Files (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<p>The campaign primarily focuses on harvesting Microsoft 365 credentials through adversary-in-the-middle (AitM) techniques, which allow attackers to hijack session cookies and bypass multi-factor authentication mechanisms.<\/p>\n<p>The kit lures unsuspecting victims through convincing emails that direct them to carefully crafted <a href=\"https:\/\/cybersecuritynews.com\/trellix-unveils-new-phishing-simulator\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing pages<\/a> impersonating legitimate services such as Adobe\u2019s Shared File platform.<\/p>\n<p>Hunt.io researchers <a href=\"https:\/\/hunt.io\/blog\/phishing-kit-targets-outlook-credentials\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the campaign while investigating open directories containing suspicious content.<\/p>\n<p>Their analysis revealed a complex infrastructure designed to efficiently capture credentials and funnel them to attacker-controlled servers.<\/p>\n<p>The researchers noted that the phishing pages are meticulously designed to mimic the look and feel of authentic login portals, making detection challenging for average users.<\/p>\n<p>When examining the server infrastructure, investigators discovered multiple folders named \u201cOV6,\u201d a telltale signature of the W3LL kit which typically positions its control panel at this location.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi-i5rjueUDXXcx-KBDHlxUBHEy3v-DW2zXdo2HrfvO1hcPxGTyep69KcCMQv-Q-lbfeBISvXMLpkFoWQUcYwE11ew56w35AwiqexDMzmMwXozh23ETBN_1zhnQUG-BqMCsdcc-a0KjfWhEjZmACxhrJLVKRXydRD0Cbzv_lW8eDHXDcVvDbEONzff12hc\/s16000\/wfiles.html%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">wfiles.html (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<p>The phishing flow begins when users encounter a page mimicking Adobe\u2019s Shared File service, prompting them to log in to access a purportedly shared document. <\/p>\n<p>Upon entering credentials, the information is transmitted via a POST request to attacker infrastructure at teffcopipe[.]com\/wazzy.php for harvesting.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Technical Analysis of Obfuscation Techniques<\/strong><\/h2>\n<p>The W3LL kit employs sophisticated obfuscation techniques to evade detection and analysis.<\/p>\n<p>One notable method is the use of lonCube, an encryption tool for PHP code that significantly slows down research and reverse engineering efforts.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEggENMgqnGrBXnBYZY6dlqgM_cEwGP4t3P4CPIGV3neEQDr9-nFibqKX2QrB3uynKxP1u5ob7HXrTSYj9rUmr4VB9aznzTlrT-zaQXzIUjq2e1Kh-Vzpw8yw5BbmGFycffgv3g3VETRym9vrD74NQ1UKPofAdJ1zSRF3msWmN2tcUiIISfC06bJHl30Mus\/s16000\/OV6_Encoded%2520folder%2520contents%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">OV6_Encoded folder contents (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<p>Examining the OV6_ENCODED directory reveals heavily <a href=\"https:\/\/cybersecuritynews.com\/highly-obfuscated-net-sectoprat\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> PHP files designed to hide the kit\u2019s functionality from security researchers and automated scanning tools.<\/p>\n<p>The kit\u2019s configuration is managed through a config.php file that contains crucial operational parameters.<\/p>\n<p>A snippet of this file, provides insights into how the toolkit functions, including credential handling processes and data exfiltration methods.<\/p>\n<p>This configuration allows attackers to customize various aspects of their <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-campaign-attacking-investors\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a>, from visual elements of the phishing pages to the destination of stolen credentials.<\/p>\n<p>Network indicators associated with this campaign include the open directory at 192.3.137[.]252:443 and additional infrastructure at teffcopipe[.]com pointing to 5.63.8[.]243, utilizing Let\u2019s Encrypt certificates valid until March 19, 2024.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><strong>Equip your SOC team with deep threat analysis for faster response -&gt;\u00a0<\/strong><a href=\"https:\/\/app.any.run\/plans?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=spring_offer&amp;utm_content=plans&amp;utm_term=190525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Get Extra \ud835\udde6\ud835\uddee\ud835\uddfb\ud835\uddf1\ud835\uddef\ud835\uddfc\ud835\ude05 \ud835\uddf9\ud835\uddf6\ud835\uddf0\ud835\uddf2\ud835\uddfb\ud835\ude00\ud835\uddf2\ud835\ude00 for Free<\/strong><\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/w3ll-phishing-kit-actively-attacking-users\/\">W3LL Phishing Kit Actively Attacking Users to Steal Outlook Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/w3ll-phishing-kit-actively-attacking-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>W3LL Phishing Kit Actively Attacking Users to Steal Outlook Login Credentials A sophisticated phishing campaign utilizing the W3LL Phishing Kit has been actively targeting users\u2019 Microsoft Outlook credentials through elaborate impersonation techniques. First identified by Group-IB in 2022, this phishing-as-a-service (PhaaS) tool has evolved into a comprehensive ecosystem complete with its own marketplace called W3LL [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4072","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4072"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4072"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4072\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}