FBI, Indonesia take down W3LL phishing tool
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是FBI和印尼警方联手打击了一个叫做W3LL的钓鱼工具。这个工具允许黑客用500美元创建看起来像真实登录页面的假网站。他们还逮捕了开发者,并扣押了相关域名。 文中提到这个平台不仅仅是钓鱼,还是一个完整的网络犯罪平台,设计用来诱骗用户输入凭证,绕过多重认证。背后有一个叫W3LLSTORE的市场,提供登录细节和远程桌面访问。 从2019到2023年,该平台广告显示有超过25,000个账户被入侵,导致超过2000万美元的欺诈。Group IB的专家指出,该平台服务于至少500个威胁行为者,并在2022年10月至2023年7月间攻击了56,000多个企业Microsoft 365账户。 尽管W3LLSTORE在2023年关闭,但通过加密消息平台继续运营,在2023至2024年间影响了全球17,000名受害者。开发者G.L涉嫌收集并转卖被入侵账户的访问权限。 FBI指出网络诈骗在2025年占IC3报告损失的绝大多数,高达176亿美元。此外,FBI在2026年关闭了两个大型网络犯罪论坛,并与尼日利亚警方合作逮捕了另一个钓鱼工具RaccoonO365的开发者。 总结时要涵盖关键点:FBI和印尼警方行动、W3LL工具的功能、涉及金额、影响范围以及后续行动。确保内容简洁明了,不超过100字。 </think> FBI与印尼警方合作打击了一个名为W3LL的钓鱼工具平台,该平台允许黑客以低价创建虚假登录页面并绕过多重认证。该工具涉及超5.6万企业账户被攻击,并通过关联市场非法获利数百万美元。 FBI已逮捕开发者并查封相关域名及工具。 2026-4-13 17:4:23 Author: therecord.media(查看原文) 阅读量:12 收藏

A widely used phishing tool called W3LL was disrupted by the FBI and law enforcement agencies in Indonesia on Friday. The phishing kit allowed hackers to create fake websites that looked like legitimate login portals for just $500. 

The FBI’s Atlanta office said it “identified and seized infrastructure facilitating the phishing service.” The Indonesian National Police arrested the alleged developer behind the platform and also seized some critical domains tied to the platform. 

"This wasn’t just phishing — it was a full-service cybercrime platform," said Marlo Graham, a special agent in charge at FBI Atlanta.

The platform was designed to trick victims into entering credentials into fake portals, which would be captured and used to bypass multifactor authentication, allowing cybercriminals to maintain their access to accounts.

The FBI said the phishing kit was backed by an online marketplace called W3LLSTORE that offered up individuals’ login details and credentials for remote desktops. 

The platform advertised more than 25,000 compromised accounts for sale between 2019 and 2023 — enabling cybercriminals to “steal thousands of victims’ account credentials and attempt more than $20 million in fraud.”

Cyber experts at Group IB said the platform “served a closed community of at least 500 threat actors who could purchase a custom phishing kit called W3LL Panel, designed to bypass MFA, as well as 16 other fully customized tools for business email compromise (BEC) attacks.”

“Group-IB investigators identified that W3LL’s phishing tools were used to target over 56,000 corporate Microsoft 365 accounts in the USA, UK, Australia and Europe between October 2022 and July 2023,” the company said, noting that it was reporting its findings to law enforcement. In the last 10 months, the researchers said, W3LL’s earnings likely reached half a million dollars.

The W3LLSTORE shut down in 2023 but lived on through encrypted messaging platforms, according to the FBI. Cybercriminals continued marketing the tool, and from 2023 to 2024 it was used in attacks on 17,000 victims globally. 

The developer behind the platform, who the FBI identified only as G.L, allegedly personally collected and resold access to compromised accounts.

The FBI said last week that cyber-enabled fraud accounted for the overwhelming majority of all losses reported to their Internet Crime Complaint Center (IC3) in 2025, with a staggering $17.6 billion stolen.

The agency has taken down two large cybercrime forums in 2026 — subscription-based platform Leakbase and Russian marketplace RAMP

The FBI also worked with Nigerian police in December to arrest one of the alleged developers behind the RaccoonO365 subscription phishing kit. Like W3LLSTORE, RaccoonO365 was used to create fake Microsoft login portals aimed at harvesting user credentials and unlawfully accessing the email platforms of corporate, financial, and educational institutions.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/phishing-takedown-indonesia-fbi
如有侵权请联系:admin#unsafe.sh