A recent report by Group-IB revealed that the Outsider Phishing Kit, a phishing-as-a-service operation run by a threat actor named ChenLun, has continued its malicious activities following a law enforcement takedown. Despite the efforts that included a civil lawsuit by Google and a coordinated initiative named Operation Ghost Hook, over 700 new phishing pages emerged within a month.
The kit, which has been linked to more than 100,000 phishing pages across 54 countries, offers various templates targeting diverse sectors. Notably, it employs sophisticated methods for capturing victims' personal details, including real-time interaction capabilities that enhance credential theft. Researchers emphasize the importance of monitoring and tracking these phishing attempts to mitigate risks.