A phishing-as-a-service (PaaS) operation known as Outsider has continued to generate new campaigns despite a coordinated takedown effort in June, with more than 700 new phishing pages identified within a month of the disruption. Researchers at Group-IB have tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, identifying over 100,000 phishing pages targeting at least 54 countries between December 2025 and May 2026.
The persistent activity was observed after Google filed a civil lawsuit against the group on June 12. The following day, the FBI's Cyber Division, in collaboration with Google and Lumen's Black Lotus Labs, announced "Operation Ghost Hook," a coordinated effort that seized the group's core administrative servers, a Shopify storefront, approximately $100,000 from its payment wallets, and thousands of domains registered through U.S. providers.
Before Operation Ghost Hook, Group-IB had linked over 10,000 unique domains to Outsider. Since the takedown, more than 700 additional domains have been identified, indicating that affiliates continued to use the kit despite efforts to dismantle its infrastructure. The platform offered 267 pre-made phishing templates targeting various sectors, including financial services, brokerage firms, telecommunications providers, postal services, government, and toll systems.
Campaigns were primarily delivered via SMS and distributed through a Telegram ecosystem used for selling the kit and managing affiliates. ChenLun has since deleted this Telegram channel. Prior to its suspension, the main group had over 5,000 subscribers and more than 230 users who had purchased the kit.
One observed smishing campaign impersonated Singapore's Land Transport Authority (LTA), creating a sense of urgency around an alleged data synchronization issue. These messages included instructions designed to bypass handset spam filtering. The fraudulent portal collected vehicle registration numbers and phone numbers before redirecting victims to fake payment screens. The harvested phone numbers were intended for intercepting SMS authentication codes at a later stage.
The Outsider Phishing Kit incorporates adversary-in-the-middle (AiTM) capabilities, allowing operators to interact with victims during the phishing flow. Operators could dynamically serve SMS, email, PIN, or app-based multifactor authentication (MFA) challenges and redirect victims back to earlier pages to request additional payment information. The kit also utilized WebSockets for real-time communication between phishing pages and an operator panel, transmitting data entered by victims instantly, even if a user abandoned a form before submission.
Group-IB identified JavaScript components designed to capture financial details, bank credentials, PayPal information, and authentication codes. The researchers also found mechanisms for tracking victims across browser sessions and detecting security crawlers. The phishing pages consistently used an alphabetical prefix in their file-naming convention, which marked the victim's stage in the attack flow.
Organizations are advised to track new phishing pages through these file-name signatures to facilitate takedowns. Continuous monitoring for SMS-linked brand abuse is also recommended. Individuals should verify alerts through official applications rather than clicking links in messages.






