Outlook Users Targeted by Active W3LL Phishing Kit Attacks

Outlook Users Targeted by Active W3LL Phishing Kit Attacks

A highly advanced phishing operation using the W3LL Phishing Kit has been relentlessly targeting Microsoft Outlook login credentials through sophisticated impersonation methods.

Initially discovered by Group-IB in 2022, this phishing-as-a-service (PhaaS) platform has since developed into a fully-fledged ecosystem, featuring the W3LL Store—a marketplace where cybercriminals can tailor their phishing attacks to suit their precise objectives.

W3LL Phishing Kit Artifacts (Source – Hunt.io)

This phishing campaign is primarily aimed at extracting Microsoft 365 login credentials using advanced adversary-in-the-middle (AitM) strategies. These techniques enable cybercriminals to intercept session cookies and bypass multi-factor authentication safeguards.

Victims are enticed by well-crafted emails that lead them to expertly designed phishing websites masquerading as trusted platforms, including Adobe’s Shared File service.

Hunt.io researchers uncovered the campaign during their probe into open directories containing suspicious files. Their findings pointed to a sophisticated infrastructure built to capture login credentials and direct them to servers controlled by the attackers.

The phishing pages are precisely engineered to replicate legitimate login screens, making them difficult for average users to distinguish from authentic portals.

Upon analyzing the server setup, investigators found several directories labeled “OV6”—a clear indicator of the W3LL kit, which often places its control panel in these specific folders.

wfiles.html (Source – Hunt.io)

The phishing attack is initiated when users are directed to a fraudulent page designed to resemble Adobe’s Shared File service, where they are prompted to log in to view a supposedly shared document.

Once credentials are entered, they are sent through a POST request to attacker-controlled servers at teffcopipe[.]com/wazzy.php for theft and exploitation.

Technical Overview of Concealment Methods

The W3LL Phishing Kit employs advanced techniques to mask its malicious activities and hinder detection efforts.

A key strategy includes the use of IonCube, a tool for encrypting PHP code, which significantly complicates research and reverse engineering, making it harder for cybersecurity professionals to analyze and dismantle the attack.

Contents of the OV6_Encoded Folder (Source – Hunt.io)

An investigation into the OV6_ENCODED directory reveals heavily obfuscated PHP files, strategically crafted to conceal the kit’s operations from security analysts and automated detection systems.

Central to the toolkit’s configuration is a file named config.php, which contains key parameters that govern its functions.

A look at part of this file sheds light on the processes involved in handling stolen credentials and exfiltrating data, offering a glimpse into the inner workings of the phishing operation.

This configuration file gives attackers the flexibility to tailor various aspects of their attack, such as the appearance of phishing pages and the redirection of compromised credentials.

Key network indicators tied to this attack include an open directory at 192.3.137[.]252:443, alongside additional infrastructure hosted on teffcopipe[.]com, pointing to 5.63.8[.]243, with certificates issued by Let’s Encrypt valid until March 19, 2024.

More Articles & Posts