HomeRisk ManagementsOutsider Phishing Kit Thrives After Takedown with 700 New Pages

Outsider Phishing Kit Thrives After Takedown with 700 New Pages

Published on

spot_img

Phishing-as-a-Service Operation Resilient Despite Takedown Efforts

In a recent turn of events within the cybersecurity landscape, a phishing-as-a-service (PaaS) operation has demonstrated remarkable resilience, generating a slew of new phishing campaigns even in the wake of a coordinated takedown initiative. According to findings released by cyber intelligence firm Group-IB, over 700 new phishing pages have emerged within just one month following the disruption of this illicit enterprise.

The operation in question is known as the Outsider Phishing Kit, linked to a threat actor identified as ChenLun. Group-IB researchers tracked the kit closely and reported that between December 2025 and May 2026, it had facilitated the creation of more than 100,000 phishing pages targeting a staggering 54 countries or more. The sheer scale of this operation raises important questions about the effectiveness of current cybersecurity measures against such sophisticated criminal tactics.

As detailed in a research report published on September 3, the resilience of this phishing operation persisted even after significant legal actions took place. On June 12, Google filed a civil lawsuit against the group, which was promptly followed by an announcement from the FBI’s Cyber Division on June 13 regarding a coordinated effort involving both Google and Lumen’s Black Lotus Labs. This initiative, termed Operation Ghost Hook, was aimed at dismantling the operational backbone of ChenLun’s phishing scheme.

The FBI reported commendable progress from this operation, revealing that it managed to seize the group’s core administrative servers, dismantle a Shopify storefront used for transactional purposes, and retrieve approximately $100,000 from payment wallets associated with the operation. Furthermore, thousands of phishing domains registered through U.S. providers were also taken down, indicating a robust enforcement effort against cybercrime.

However, despite these significant efforts, the resilience of the Outsider operation has come to the forefront. Prior to Operation Ghost Hook, Group-IB had already linked over 10,000 unique domains to the Outsider initiative. Following the takedown, the researchers identified more than 700 new domains, indicating that various affiliates continue utilizing the phishing kit, thereby undermining the impact of the intervention.

The nature of the phishing campaigns utilizing the Outsider Kit has shown to be highly diversified. The platform itself includes an extensive library of phishing templates—267 in total—targeting a wide range of sectors. These sectors include financial services, brokerage firms, telecom providers, governmental organizations, and toll systems. The delivery mechanism for these phishing attempts typically involves SMS messages, supplemented by an ecosystem on Telegram designed for selling the kit and managing affiliates.

ChenLun, the operator behind this extensive network, recently deleted a Telegram channel associated with the operation. Before its suspension, this channel boasted over 5,000 subscribers and featured more than 230 users who had purchased the phishing kit, illustrating the significant market demand and robust community surrounding such malicious tools.

In examining the sophistication of the phishing campaigns, researchers highlighted a particularly concerning smishing campaign impersonating Singapore’s Land Transport Authority (LTA). Messages were crafted to incite urgency regarding alleged data synchronization issues and included illicit instructions on bypassing the device’s spam filters. This tactic enabled the cloned portal to harvest sensitive information such as vehicle registration numbers and phone numbers, redirecting victims to phony payment screens. The information collected is suspected to be employed in intercepting SMS authentication codes at later stages, revealing the calculated nature of these attacks.

The Outsider Phishing Kit also incorporates advanced adversary-in-the-middle (AiTM) capabilities, ensuring that operators can interact with victims during the phishing flow. This feature enables the dynamic serving of multifactor authentication challenges, allowing attackers to request further personal information under the guise of security checks. Notably, the kit utilizes WebSocket technology, facilitating live communication between the phishing pages and an operator panel, which can relay victim data in real time—even in instances where users abandon forms before submission.

Group-IB has identified various JavaScript components employed by the kit designed to capture sensitive financial details, bank credentials, PayPal information, and authentication codes. Moreover, the researchers discovered tracking mechanisms intended for monitoring victims across different browser sessions while circumventing security measures set up to detect such threats.

To address this evolving threat landscape, Group-IB advocates for organizations to vigilantly track the emergence of new phishing pages, recommending the use of specific file-naming conventions associated with these pages to expedite takedown processes. Furthermore, the firm advises individuals to stay alert for SMS-linked brand abuse and always verify alerts through official applications rather than relying on potentially compromised message links.

The resilience of the Outsider Phishing Kit showcases the ongoing challenges in the cybersecurity realm and necessitates a more proactive approach in bolstering defenses against such sophisticated tactics.

Source link

Latest articles

OpenAI Launches $1 Billion Cyber Defense Initiative for Small Utilities

OpenAI’s Initiatives in Cybersecurity: A Call for Collective Defense In a recent visit to North...

Huntress Warns of Malware Spread Through Hijacked ScreenConnect Installs

Huntress Unveils a Self-Propagating Malware Campaign Targeting ScreenConnect Installations In a significant revelation, cybersecurity firm...

Proofpoint Integrates OpenAI GPT Cyber Models into Security Operations to Accelerate Threat Investigation for Defenders

Proofpoint Unveils SOC Analyst Agent, Merging OpenAI's Expertise for Enhanced Threat Investigation Sunnyvale, California –...

More like this

OpenAI Launches $1 Billion Cyber Defense Initiative for Small Utilities

OpenAI’s Initiatives in Cybersecurity: A Call for Collective Defense In a recent visit to North...

Huntress Warns of Malware Spread Through Hijacked ScreenConnect Installs

Huntress Unveils a Self-Propagating Malware Campaign Targeting ScreenConnect Installations In a significant revelation, cybersecurity firm...