TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

FBI Dismantles $20m Phishing Operation W3LL

2026-04-13 · Read original ↗

ATT&CK techniques detected

4 predictions
T1566.002Spearphishing Link
99%
“to as ‘ g. l. ’ w3ll : a complete phishing ecosystem for bec attacks w3ll was first discovered in 2023 by cybersecurity firm group - ib. in a september 2023 report, the firm ’ s researchers claimed the threat actor behind the phishing operation had been operating since at least 2…”
T1657Financial Theft
58%
“fbi dismantles $ 20m phishing operation w3ll us and indonesian law enforcement authorities have taken down a large - scale phishing network that has plotted over $ 20 million in fraud. spearheaded by the fbi atlanta field office, the operation targeted w3ll, a phishing kit which …”
T1566.001Spearphishing Attachment
53%
“not just a marketplace but a complex phishing ecosystem. the fully compatible custom toolset covered almost the entire kill chain of business email compromise ( bec ) and could be used by cybercriminals of all technical skill levels.”
T1566.002Spearphishing Link
46%
“fbi dismantles $ 20m phishing operation w3ll us and indonesian law enforcement authorities have taken down a large - scale phishing network that has plotted over $ 20 million in fraud. spearheaded by the fbi atlanta field office, the operation targeted w3ll, a phishing kit which …”

Summary

The W3LL phishing kit has been associated with fraud attempts totaling $20m