Outsider phishing kit global victimology map | Image: Group-IB
At a Glance
- Actor or group: Threat actor known as “ChenLun” and affiliated subscribers.
- Activity type: Phishing-as-a-Service (PhaaS), Adversary-in-the-Middle (AiTM), and credential theft.
- Targets or victims: Mobile users in over 54 countries; impersonates banks, postal services, and toll systems.
- Scale: Over 100,000 phishing pages. The FBI claims the platform is linked to 3.87 million stolen cards and an estimated $1.9 billion in losses.
- Jurisdiction or law-enforcement status: Targeted by the FBI, Google, and Lumen in “Operation Ghost Hook”; operators allegedly remain at large.
- Source: Group-IB, FBI, and Google civil lawsuit filings.
TL;DR
The Outsider Phishing Kit continues to power widespread smishing campaigns despite international law enforcement intervention. Authorities recently disrupted the operation during Operation Ghost Hook. However, security researchers have already spotted hundreds of new malicious domains operating the ChenLun Outsider PhaaS kit.
What Happened
A massive cybercrime network has commoditized credential theft. The operation relies on the Outsider Phishing Kit to harvest financial data in real time. Threat actors use smishing texts to drive victims to fake websites. These messages impersonate government agencies, postal services, and toll systems. For example, researchers observed texts impersonating the Singapore Land Transport Authority. The texts contained explicit instructions helping victims bypass their smartphone spam filters.
Once victims click the link, they land on a fraudulent payment portal. The kit utilizes Adversary-in-the-Middle (AiTM) capabilities. This technology intercepts authentication flows and bypasses multi-factor authentication (MFA). A malicious JavaScript file transmits typed information directly to the operator. It steals data even if the victim abandons the session before hitting submit.
The Outsider PhaaS kit includes a live control panel. Operators can dynamically serve contextual 2FA challenges. They can prompt victims for SMS codes, emails, or PINs based on the institution’s actual security requirements. The kit encrypts all stolen data utilizing the AES-CTR algorithm. This encryption helps the malware hide from basic network firewalls.
The kit relies on a configuration file called common.js to set up the deception. This file defines the exact visual styles, loading messages, and color palettes of the impersonated brand. The script tracks the victim’s unique session ID across browser tabs using local storage. When the data harvesting process finishes, the kit silently redirects the victim to a legitimate corporate URL. This exit strategy makes the entire interaction appear as a minor system glitch.
Who Is Behind It
Cybersecurity analysts attribute this platform to a threat actor known as “ChenLun.” Researchers hold high confidence in this attribution based on Telegram channel activity. Prior to the recent takedown, ChenLun managed an active Telegram ecosystem. The main public group boasted over 5,000 subscribers. More than 230 active users had reportedly purchased the kit.
The subscription model lowered the technical barrier to entry. Affiliates allegedly paid $88 per week or $200 per month for access. Subscribers gained access to 267 prebuilt phishing templates. The developer utilized a strict naming convention for the HTML pages. This alphabetical system guided affiliates through the phishing workflow.
The FBI indictment charges the network members with racketeering, wire fraud, and trademark infringement. The developers updated the codebase regularly to avoid detection. They provided a centralized web dashboard for their clients. Affiliates could view victim interactions, manage harvested data, and trigger new authentication prompts. This dashboard made the cybercrime product highly accessible for non-technical criminals. Google and the FBI suspect the primary operators are based in China. However, authorities note that extraditing the unnamed defendants remains highly unlikely.
Impact or Scale
The scale of this cybercrime operation is staggering. Between December 2025 and May 2026, Group-IB identified over 100,000 phishing pages. These campaigns targeted victims across more than 54 countries. The operation impersonated financial services, telecommunications providers, and government agencies.
On June 12, 2026, Google filed a civil lawsuit against the Outsider group. The very next day, the FBI announced a coordinated disruption effort dubbed Operation Ghost Hook. The FBI, Google, and Lumen’s Black Lotus Labs dismantled the group’s core infrastructure. Authorities seized management servers, a Shopify storefront, and roughly $100,000 in cryptocurrency. According to the FBI, the platform is linked to an estimated $1.9 billion in historical losses and 3.87 million stolen credit cards.
What Comes Next and How to Stay Protected
Despite the sweeping Operation Ghost Hook takedown, the threat actively persists. The Outsider Phishing Kit remains in the hands of independent affiliates. Within one month of the disruption, Group-IB discovered over 700 new phishing pages. The developer deleted their primary Telegram channel to hide from law enforcement. However, the software itself continues to function on newly registered domains.
Google is now collaborating with major telecommunications providers. They are working with AT&T, T-Mobile, and Verizon to block malicious text messages at the network level. Users must remain highly skeptical of urgent text messages. Never click links in unexpected SMS messages regarding tolls, package deliveries, or account issues. Always navigate directly to the official website or use a verified mobile application. Organizations should monitor for newly registered domains that mimic their brand names. Deploying modern FIDO2 security keys can also block AiTM attacks completely.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!