logo

Outsider Phishing Kit Survives Takedown With 700 New Pages

ID: d2fa7d92-aae5-5c63-a6be-e390431a9d06

STIX ID: report--d2fa7d92-aae5-5c63-a6be-e390431a9d06

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

...
...

Group-IB tracked the Outsider Phishing Kit run by an actor known as ChenLun and found it produced over 100,000 phishing pages targeting 54+ countries (Dec 2025–May 2026); despite a coordinated takedown (Operation Ghost Hook) that seized servers, domains and payment wallets, affiliates continued to spin up new pages. The kit provided ready-made templates for financial and government targets, distributed via SMS and Telegram, and supported adversary-in-the-middle (AiTM) capabilities — live operator interaction, dynamic MFA challenge capture, WebSocket data exfiltration, and mechanisms to harvest SMS numbers for later interception — with recommendations to monitor SMS-linked brand abuse and track file-name signatures for takedown triggers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.