Skip to main content
Emerging ThreatsMalware & Ransomware

Outsider Phishing Kit Persists After Takedown Effort

Rows of rack-mounted servers in a dimly lit, cramped server room.

More than 700 new phishing pages were created within a month of a coordinated takedown that seized servers, domains and roughly $100,000 in payment wallets, showing the Outsider Phishing Kit remained operational even after legal and law‑enforcement action.

Outsider Phishing Kit continues after Operation Ghost Hook

Researchers at Group‑IB reported that the Outsider Phishing Kit — operated by a threat actor known as ChenLun — continued generating campaigns after a takedown effort. Group‑IB tracked more than 100,000 phishing pages targeting 54 or more countries between December 2025 and May 2026, and had linked more than 10,000 unique domains to Outsider prior to the coordinated disruption. In the month following the action, the company identified over 700 additional domains, evidence that affiliates continued to deploy the kit despite the seizure of core infrastructure.

Operation Ghost Hook: seizures, lawsuit and claimed takedown results

Google filed a civil lawsuit against the group on June 12, and the FBI's Cyber Division announced a coordinated effort with Google and Lumen's Black Lotus Labs called Operation Ghost Hook the following day. The FBI said the operation seized the group's core admin servers, a Shopify storefront, about $100,000 from its payment wallets and thousands of domains registered through US providers. Despite those seizures and the removal of the group's Telegram channel by its operator, Group‑IB's telemetry shows affiliate activity persisted.

How the kit works: AiTM, WebSockets and real‑time credential capture

Group‑IB's analysis details a fully featured phishing‑as‑a‑service platform. The Outsider kit included adversary‑in‑the‑middle (AiTM) capabilities that could dynamically present SMS, email, PIN or app‑based multifactor authentication (MFA) challenges and redirect victims back to earlier pages to request more payment information. The researchers found that the kit used WebSockets to support live communication between the phishing pages and an operator panel, enabling data entered by victims to be transmitted in real time — even when users abandoned a form before submitting it.

JavaScript components identified by Group‑IB captured financial details, bank credentials, PayPal information and authentication codes. The platform also had mechanisms to track victims across browser sessions and to detect security crawlers. Pages followed a consistent file‑naming convention with an alphabetical prefix indicating the victim's stage in the attack flow; Group‑IB recommended using those file‑name signatures as a practical signal to spot and trigger takedowns.

LTA smishing campaign: instructions to defeat handset filtering and harvest MFA targets

Group‑IB dissected a smishing campaign impersonating Singapore's Land Transport Authority (LTA). The messages created urgency around an alleged data synchronization issue and included instructions telling recipients how to defeat their handset's spam filtering. The cloned portal collected vehicle registration numbers and phone numbers before redirecting victims to fraudulent payment screens. According to Group‑IB, the harvested phone numbers were intended for later interception of SMS authentication codes — a clear use case for the kit's AiTM flow and real‑time operator interactions.

What this means for security teams, enterprises, and end users

  • Security teams and technologists: Group‑IB's findings point to the need for continuous monitoring for SMS‑linked brand abuse and for detection rules that look for the kit's file‑name conventions and WebSocket traffic patterns. The presence of real‑time operator panels and AiTM flows changes detection priorities from static URL blocking to behavioral and session analysis.
  • Enterprises and brand defenders: The Outsider kit's 267 ready‑made templates — covering financial services, brokerage firms, telecommunications providers, postal services, government and toll systems — means defenders should prioritize protections around customer messaging channels and the verification pathways customers use, including official apps rather than links in messages.
  • End users and consumers: Group‑IB specifically advised individuals to verify alerts through official apps rather than message links. The LTA example shows campaigns that instruct users to bypass device spam filters and that collect phone numbers explicitly to target authentication codes; treating unsolicited urgent messages with skepticism remains a central safeguard.

The record from Group‑IB paints a picture of a resilient PaaS operation: legal action and server seizures removed parts of the infrastructure, but the kit's templates, affiliate ecosystem and live‑interaction capabilities allowed new pages to appear within weeks. Tracking file‑naming conventions, monitoring SMS‑linked brand abuse, and emphasizing app‑based verification are the concrete countermeasures the researchers recommend as the immediate next steps.

Original story