LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
phishing

Outsider Phishing Kit Survives Takedown With 700 New Pages

Outsider phishing kit generated 700 new pages after a Google-led disruption

zeroday.news ·

A phishing-as-a-service (PaaS) operation known as Outsider has continued to generate new campaigns despite a coordinated takedown effort in June, with more than 700 new phishing pages identified within a month of the disruption. Researchers at Group-IB have tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, identifying over 100,000 phishing pages targeting at least 54 countries between December 2025 and May 2026.

The persistent activity was observed after Google filed a civil lawsuit against the group on June 12. The following day, the FBI's Cyber Division, in collaboration with Google and Lumen's Black Lotus Labs, announced "Operation Ghost Hook," a coordinated effort that seized the group's core administrative servers, a Shopify storefront, approximately $100,000 from its payment wallets, and thousands of domains registered through U.S. providers.

Before Operation Ghost Hook, Group-IB had linked over 10,000 unique domains to Outsider. Since the takedown, more than 700 additional domains have been identified, indicating that affiliates continued to use the kit despite efforts to dismantle its infrastructure. The platform offered 267 pre-made phishing templates targeting various sectors, including financial services, brokerage firms, telecommunications providers, postal services, government, and toll systems.

Campaigns were primarily delivered via SMS and distributed through a Telegram ecosystem used for selling the kit and managing affiliates. ChenLun has since deleted this Telegram channel. Prior to its suspension, the main group had over 5,000 subscribers and more than 230 users who had purchased the kit.

One observed smishing campaign impersonated Singapore's Land Transport Authority (LTA), creating a sense of urgency around an alleged data synchronization issue. These messages included instructions designed to bypass handset spam filtering. The fraudulent portal collected vehicle registration numbers and phone numbers before redirecting victims to fake payment screens. The harvested phone numbers were intended for intercepting SMS authentication codes at a later stage.

The Outsider Phishing Kit incorporates adversary-in-the-middle (AiTM) capabilities, allowing operators to interact with victims during the phishing flow. Operators could dynamically serve SMS, email, PIN, or app-based multifactor authentication (MFA) challenges and redirect victims back to earlier pages to request additional payment information. The kit also utilized WebSockets for real-time communication between phishing pages and an operator panel, transmitting data entered by victims instantly, even if a user abandoned a form before submission.

Group-IB identified JavaScript components designed to capture financial details, bank credentials, PayPal information, and authentication codes. The researchers also found mechanisms for tracking victims across browser sessions and detecting security crawlers. The phishing pages consistently used an alphabetical prefix in their file-naming convention, which marked the victim's stage in the attack flow.

Organizations are advised to track new phishing pages through these file-name signatures to facilitate takedowns. Continuous monitoring for SMS-linked brand abuse is also recommended. Individuals should verify alerts through official applications rather than clicking links in messages.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

breach

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals in the United Sta

breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web

nation-state

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University