W3LL AiTM Kit Takedown: Technicals of M365 BEC Phishing Disrupted
W3LL phishing-as-a-service enabled AiTM attacks on Microsoft 365 for BEC/wire fraud:
- Fake portals captured credentials + session data to bypass MFA,...

Created by Oscar Lankford Jr
Technical research on spear‑phishing attacks and defenses for high‑value financial institutions
Explore the latest content tracked by Financial Spear Phishing Digest
W3LL phishing-as-a-service enabled AiTM attacks on Microsoft 365 for BEC/wire fraud:
Storm-2755 executes payroll pirate attacks via these 7 spear-phishing tactics targeting Canadian financial ops:
Key technical insights from the W3LL phishing-as-a-service dismantlement:
Security leaders layer adaptive AI atop secure email gateways (SEG) like Microsoft Defender to combat evolving BEC and spear-phishing in financial...
Key indicators for crypto-targeted phishing via hosting abuse:
Key TTPs in this BEC-style attack:
Technical sourcing in deepfake vishing: Attackers grab public audio from conferences to impersonate execs.
Key implications for payment security:
2025 cybercrime losses reached $20.87B, with BEC ranking #2 after investment scams in high-value financial hits.
Key evasion tactics in AI-powered tax vishing:
VENOM spear-phishing hits C-suite execs (CEOs, CFOs) by name across 20 sectors since Nov 2025, via compromised biz emails impersonating SharePoint...
Key tactics in Hive0117's Feb-Mar 2026 campaign targeting Russian finance depts:
Key insights on layered security for spear-phishing targeting financial workflows:
JINKUSU CAM live deepfakes target financial/crypto KYC with real-time video injection.
Rapid surge in prevalence: 32,400 complaints in 2025 vs. 17,400 in 2024 and 14,200 in 2023, ranking top five cybercrimes.