30
45
45
30
30
30
30
35
30
30
Outsider Phishing Kit Survives Takedown With 700 New Pages
Group-IB found the Outsider phishing kit kept generating 700+ new phishing pages within a month of Operation Ghost Hook's takedown.
Group-IB linked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, to more than 100,000 phishing pages across 54+ countries between December 2025 and May 2026. After the FBI, Google, and Lumen's Black Lotus Labs seized core admin servers, a Shopify storefront, about $100,000, and thousands of domains under Operation Ghost Hook in June, over 700 new phishing domains appeared within a month. The kit offered 267 templates, adversary-in-the-middle MFA interception, WebSocket-based live operator communication, and SMS delivery via a Telegram affiliate ecosystem with more than 5,000 subscribers.
57
30
30
30
30
30
45
30
30
30
30
45
45
45
30
45
30
30
30
30
30
30
30
30