Outsider Phishing Kit Continues Operations Post-Takedown

Outsider Phishing Kit Continues Operations Post-Takedown

First seen 3 Sep 2026, 14:06 UTC Infosecurity-Magazinewww.group-ib.com 69.5

Article Content

Browse articles
ThreatCluster

The Outsider Phishing Kit, operated by the threat actor ChenLun, has shown resilience despite significant takedown efforts. Group-IB researchers reported over 700 new phishing pages created within a month following a civil lawsuit filed by Google against the group on June 12, 2026. The kit has been linked to over 100,000 phishing pages targeting more than 54 countries since December 2025. It employs sophisticated techniques including Adversary-in-the-Middle (AiTM) capabilities to intercept authentication flows and bypass multi-factor authentication (MFA). The phishing campaigns primarily target financial services, telecommunications, and government sectors, delivered via SMS and managed through a Telegram ecosystem. The FBI's Operation Ghost Hook aimed to dismantle the group's infrastructure but has not fully curtailed their operations. The continued emergence of new phishing pages indicates that affiliates are still actively utilizing the Outsider kit.

Key Points: • Over 700 new phishing pages identified within a month of takedown efforts. • The Outsider Phishing Kit targets over 54 countries with 267 ready-made templates. • The kit employs AiTM capabilities to bypass multi-factor authentication.

Timeline

2025-12-01
Outsider Phishing Kit identified
Group-IB began tracking the Outsider Phishing Kit, linking it to over 100,000 phishing pages.
Group-IB
2026-06-12
Google files lawsuit against Outsider group
Google initiated legal action against the ChenLun group to disrupt their phishing operations.
Group-IB
2026-06-13
Operation Ghost Hook announced
The FBI's Cyber Division, in partnership with Google and Lumen's Black Lotus Labs, launched an operation to dismantle the Outsider group's infrastructure.
Infosecurity-Magazine
2026-09-03
New phishing pages reported
Group-IB identified over 700 new phishing pages created within a month after the takedown efforts.
Infosecurity-Magazine