Back Infosecurity-Magazine Outsider Phishing Kit Survives Takedown With 700 New Pages
A phishing-as-a-service (PaaS) operation has continued generating new campaigns despite a coordinated takedown effort, with more than 700 new phishing pages identified within a month of the disruption.
Group-IB said its researchers had tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, and identified more than 100,000 phishing pages targeting 54 or more countries between December 2025 and May 2026.
The research , published on September 3, found the activity persisted after Google filed a civil lawsuit against the group on June 12 and the FBI's Cyber Division announced a coordinated effort with Google and Lumen's Black Lotus Labs, dubbed Operation Ghost Hook, the following day.
The FBI said the operation seized the group's core admin servers, a Shopify storefront, $100,000 from its payment wallets and thousands of domains registered through US providers.
New Phishing Pages Appear After Takedown
Group-IB had linked more than 10,000 unique domains to Outsider before Operation Ghost Hook. It has since identified more than 700 additional domains, indicating affiliates continued using the kit despite efforts to dismantle its infrastructure.
The platform contained 267 ready-made phishing templates covering financial services, brokerage firms, telecommunications providers, postal services, government and toll systems. The campaigns were delivered through SMS and distributed through a Telegram ecosystem for selling the kit and managing affiliates.
Researchers examined a smishing campaign impersonating Singapore's Land Transport Authority (LTA). The messages created urgency around an alleged data synchronization issue and included instructions telling recipients how to defeat their handset's own spam filtering.
The cloned portal collected vehicle registration numbers and phone numbers before redirecting victims to fraudulent payment screens. Group-IB said the harvested numbers were intended for intercepting SMS authentication codes at a later stage.
Live Interaction Supports Credential Theft
The Outsider Phishing Kit included adversary-in-the-middle (AiTM) capabilities designed to interact with victims during the phishing flow.
Group-IB said operators could dynamically serve SMS, email, PIN or app-based multifactor authentication (MFA) challenges and redirect victims back to earlier pages to request additional payment information.
The kit also used WebSockets to provide live communication between phishing pages and an operator panel. Data entered by victims could be transmitted in real time, including when a user abandoned a form before submitting it.
Group-IB identified JavaScript components that captured financial details, bank credentials, PayPal information and authentication codes. The researchers also found mechanisms for tracking victims across browser sessions and detecting security crawlers.
The pages followed a consistent file-naming convention, with an alphabetical prefix marking the victim's stage in the attack flow. Group-IB recommended that organizations track new pages through those file-name signatures to trigger takedowns.
To protect against the threat, the company also recommended continuous monitoring for SMS-linked brand abuse, and advised individuals to verify alerts through official apps rather than message links.
Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft News 16 February 2026
Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft
New Mobile Spyware ZeroDayRAT Targets Android and iOS News 10 February 2026
New Mobile Spyware ZeroDayRAT Targets Android and iOS
RedWing Android Spyware Sold as a Service on Telegram News 8 July 2026
RedWing Android Spyware Sold as a Service on Telegram
New Venom Stealer MaaS Platform Automates Continuous Data Theft News 1 April 2026
New Venom Stealer MaaS Platform Automates Continuous Data Theft
New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware News 24 March 2026
New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide Malware
What’s Hot on Infosecurity Magazine?
65% of Enterprises Have Seen AI Agents Act Out of Scope
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Healthcare Giant McKesson Investigates Data Breach Incident
Manchester Airports Group Hit by Cyber Incident
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
Manchester Airports Group Hit by Cyber Incident
DDoS Attack Hits Norwegian Government Services
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How To Enhance Security Operations with AI-Powered Defenses
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Dispelling the Myths of Defense-Grade Cybersecurity
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Revisiting CIA: Developing Your Security Strategy in the SaaS Shared Reality
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
