Phishing-as-a-Service Operation Rebounds Days After Global Takedown
A phishing-as-a-service platform known as the Outsider Phishing Kit has continued operating despite a major law enforcement disruption. Group-IB researchers tracked more than 100,000 phishing pages linked to the kit between December 2025 and May 2026, targeting victims across 54 or more countries. On June 12, Google filed a civil lawsuit against the operator, known as ChenLun, and the FBI launched Operation Ghost Hook with Google and Lumen's Black Lotus Labs, seizing admin servers, a Shopify storefront, around $100,000 in payment wallets, and thousands of domains.
Despite this action, Group-IB found more than 700 new domains tied to the kit appeared within a month, suggesting affiliates kept using it even after the main infrastructure was dismantled. The kit offered 267 ready-made phishing templates impersonating banks, telecoms, postal services, government agencies and toll systems, distributed via SMS and sold through a Telegram network with thousands of subscribers before it was shut down.
One example examined by researchers involved a fake message impersonating Singapore's Land Transport Authority, which pressured recipients into visiting a cloned portal that collected vehicle registration and phone numbers—likely for intercepting SMS-based authentication codes later. The kit also included adversary-in-the-middle capabilities to actively manipulate victims during the phishing process.