Outsider Phishing Kit Survives Takedown With 700 New Pages
ID: d2fa7d92-aae5-5c63-a6be-e390431a9d06
STIX ID: report--d2fa7d92-aae5-5c63-a6be-e390431a9d06
Feed Name: Infosecurity Magazine (News)
Group-IB tracked the Outsider Phishing Kit run by an actor known as ChenLun and found it produced over 100,000 phishing pages targeting 54+ countries (Dec 2025–May 2026); despite a coordinated takedown (Operation Ghost Hook) that seized servers, domains and payment wallets, affiliates continued to spin up new pages. The kit provided ready-made templates for financial and government targets, distributed via SMS and Telegram, and supported adversary-in-the-middle (AiTM) capabilities — live operator interaction, dynamic MFA challenge capture, WebSocket data exfiltration, and mechanisms to harvest SMS numbers for later interception — with recommendations to monitor SMS-linked brand abuse and track file-name signatures for takedown triggers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
