Outsider phishing kit generated 700 new pages after a Google-led disruption

A phishing-as-a-service (PaaS) operation known as Outsider has continued to generate new campaigns despite a coordinated takedown effort in June, with more than 700 new phishing pages identified within a month of the disruption. Researchers at Group-IB have tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, identifying over 100,000 phishing pages targeting at least 54 countries between December 2025 and May 2026.
The persistent activity was observed after Google filed a civil lawsuit against the group on June 12. The following day, the FBI's Cyber Division, in collaboration with Google and Lumen's Black Lotus Labs, announced "Operation Ghost Hook," a coordinated effort that seized the group's core administrative servers, a Shopify storefront, approximately $100,000 from its payment wallets, and thousands of domains registered through U.S. providers.
Before Operation Ghost Hook, Group-IB had linked over 10,000 unique domains to Outsider. Since the takedown, more than 700 additional domains have been identified, indicating that affiliates continued to use the kit despite efforts to dismantle its infrastructure. The platform offered 267 pre-made phishing templates targeting various sectors, including financial services, brokerage firms, telecommunications providers, postal services, government, and toll systems.
Campaigns were primarily delivered via SMS and distributed through a Telegram ecosystem used for selling the kit and managing affiliates. ChenLun has since deleted this Telegram channel. Prior to its suspension, the main group had over 5,000 subscribers and more than 230 users who had purchased the kit.
One observed smishing campaign impersonated Singapore's Land Transport Authority (LTA), creating a sense of urgency around an alleged data synchronization issue. These messages included instructions designed to bypass handset spam filtering. The fraudulent portal collected vehicle registration numbers and phone numbers before redirecting victims to fake payment screens. The harvested phone numbers were intended for intercepting SMS authentication codes at a later stage.
The Outsider Phishing Kit incorporates adversary-in-the-middle (AiTM) capabilities, allowing operators to interact with victims during the phishing flow. Operators could dynamically serve SMS, email, PIN, or app-based multifactor authentication (MFA) challenges and redirect victims back to earlier pages to request additional payment information. The kit also utilized WebSockets for real-time communication between phishing pages and an operator panel, transmitting data entered by victims instantly, even if a user abandoned a form before submission.
Group-IB identified JavaScript components designed to capture financial details, bank credentials, PayPal information, and authentication codes. The researchers also found mechanisms for tracking victims across browser sessions and detecting security crawlers. The phishing pages consistently used an alphabetical prefix in their file-naming convention, which marked the victim's stage in the attack flow.
Organizations are advised to track new phishing pages through these file-name signatures to facilitate takedowns. Continuous monitoring for SMS-linked brand abuse is also recommended. Individuals should verify alerts through official applications rather than clicking links in messages.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets