securityonline.info 8 Sept 2026, 13:02 UTC

Outsider Phishing Kit Resurfaces After Global Law Enforcement Takedown

Outsider Phishing Kit Resurfaces After Global Law Enforcement Takedown
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
ChenLun

THE Outsider Phishing Kit, a PhaaS platform linked to the threat actor “ChenLun,” has again demonstrated its reach despite a high-profile law-enforcement disruption. Researchers describe a sizeable operation that used smishing to lure mobile users to fake portals impersonating banks, postal services, and toll operators.

Real-time credential harvesting was enabled by an Adversary-in-the-Middle (AiTM) framework, with a malicious JavaScript component transmitting data directly to the operators and allowing the interception of authentication flows, including MFA, even if victims abandoned the process.

Group-IB, the FBI, and Google-linked filings detail a large-scale network. Between December 2025 and May 2026, investigators logged more than 100,000 phishing pages across 54 countries. The FBI’s involvement culminated in a coordinated action in June 2026 (Operation Ghost Hook), with Google and Lumen’s Black Lotus Labs dismantling core infrastructure, seizing servers and a Shopify storefront, and recovering around $100,000 in cryptocurrency.

Authorities estimate that the platform is connected to about 3.87 million stolen cards and roughly $1.9 billion in losses historically. The primary operators are alleged to be based in China, though extradition is considered unlikely; the operators reportedly shifted to independent affiliates after the takedown.

Despite the disruption, the threat remains active. Within a month, security firms observed hundreds of new domains hosting the ChenLun Outsider PhaaS kit, and the developer reportedly dissolved the main Telegram channel to evade authorities. Researchers warn that the ecosystem can still operate on freshly registered domains, underscoring the need for vigilant monitoring of brand impersonations and加强 user awareness around smishing threats.

View full article

Article by CyberSIXT