W3LL Microsoft 365 adversary-in-the-middle phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The W3LL phishing operation turned into a high-volume Microsoft 365 credential-theft campaign, exposing more than 17,000 victims worldwide to BEC risk. The kit used adversary-in-the-middle proxies to intercept passwords, MFA passcodes, and session cookies. That access could bypass MFA and let attackers enter mailboxes, monitor email, and redirect payments. The operation mattered because it combined phishing delivery with reusable access brokerage and post-compromise fraud.
Related Happenings
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Timeline
-
13.04.2026 21:55 2 articles · 3mo ago
W3LL Microsoft 365 adversary-in-the-middle campaign and coordinated takedown
Campaign Scope UpdateOn April 13, 2026, the FBI Atlanta Field Office and Indonesian authorities dismantled the W3LL phishing platform and seized w3ll[.]store, ending a service that sold for $500 and used adversary-in-the-middle proxies to clone corporate login portals, intercept credentials, one-time MFA passcodes, and session cookies, and support business email compromise attacks against Microsoft 365 corporate accounts. The operation was linked to more than 17,000 victims worldwide and a marketplace that facilitated the sale of more than 25,000 compromised accounts, with stolen access also brokered through W3LLSTORE and encrypted messaging platforms.
Show sources
- FBI takedown of W3LL phishing service leads to developer arrest — www.bleepingcomputer.com — 13.04.2026 21:55
- FBI takedown of W3LL phishing service leads to developer arrest — www.bleepingcomputer.com — 13.04.2026 21:55