Description

On September 6th, 2023, cybersecurity firm Group-IB provided a comprehensive account of the activities and evolution of a notorious threat actor known as W3LL. This individual has gained notoriety for developing malicious tools specifically tailored for Business Email Compromise (BEC) groups. W3LL's illicit journey commenced around 2017 with the introduction of a bulk email sending tool called W3LL SMTP Sender, initially employed for spamming purposes. However, it was in 2018 that W3LL truly rose to prominence by launching the W3LL Store, an English-speaking marketplace catering to a restricted community of cybercriminals. Within its arsenal of 17 tools, the most noteworthy is the W3LL Panel, meticulously designed to bypass multi-factor authentication (MFA) systems. This assortment of tools covers the entire spectrum of BEC operations, from victim selection to the deployment of phishing schemes featuring weaponized attachments, ultimately culminating in the delivery of phishing emails to victims' inboxes. W3LL's expertise is evident in its ability to elude detection by hosting these tools on compromised web servers and services. The techniques employed include the utilization of obfuscation methods for email headers and text bodies. Additionally, W3LL delivers phishing links through attachments rather than directly embedding them in emails. To compromise Microsoft 365 accounts, W3LL employs an adversary/man-in-the-middle (AitM/MitM) technique, intercepting communication between victims and Microsoft servers through the W3LL Panel, with the W3LL Store serving as a backend system. Once the victim's authentication session cookie is obtained, the account is compromised, and a counterfeit PDF document is presented to make the login attempt appear legitimate. Furthermore, W3LL offers the CONTOOL tool, which automates the process of discovering victim data and provides features to monitor, filter, and modify incoming emails. It can even send notifications to users on Telegram based on specific keywords. The most coveted tool in W3LL's arsenal, the W3LL Panel, is priced at $500 for three months, with a $150 monthly renewal fee, requiring a license for activation. Over its five-year existence, W3LL has amassed a customer base of more than 500 cybercriminals, offering an astonishing array of over 12,000 items. These items include compromised web services, SSH and RDP servers, hosting and cloud service accounts, business email domains, VPN accounts, and hijacked email accounts. Between October 2022 and July 2023, W3LL reportedly generated over $500,000 in estimated turnover by selling more than 3,800 items.