ZeroHour
Story · 1 source · 1 articlefirst updated ()

Outsider Phishing Kit Rebounds With 700+ New Pages Within a Month of Operation Ghost Hook Takedown

highThreat actorexploited in the wildimportance 72
What's new: Initial merged summary for this story (no prior version). The news is the post-takedown rebound: within a month of the June 2026 Operation Ghost Hook seizures, the Outsider kit had already generated 700+ new phishing pages, showing the disruption did not stop operations; both outlets published their coverage on 2026-09-03, and the new guidance is to use the kit's file-name signatures to trigger…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Group-IB found the Outsider phishing-as-a-service kit, run by a threat actor tracked as ChenLun, produced 100,000+ phishing pages across 54+ countries from December 2025 to May 2026; after the FBI, Google and Lumen's Black Lotus Labs seized its core admin…

Group-IB linked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, to more than 100,000 phishing pages across 54+ countries between December 2025 and May 2026 (Infosecurity Magazine). In June 2026, Operation Ghost Hook — carried out by the FBI, Google and Lumen's Black Lotus Labs — seized the kit's core admin servers, a Shopify storefront, roughly $100,000 and thousands of domains. Both outlets, citing Group-IB, report the kit nonetheless generated 700+ new phishing pages within a month of the takedown; Infosecurity Magazine's report describes them as new phishing domains in one passage, while its headline and The Hacker News call them phishing pages. The Hacker News adds that the rebound pages were distributed via Telegram. The kit offered 267 templates for finance, telecom, postal, government and toll scams, an adversary-in-the-middle component that dynamically served MFA challenges and relayed victim input in real time over WebSockets, and SMS delivery through a Telegram affiliate ecosystem with more than 5,000 subscribers. Group-IB also documented a smishing campaign impersonating Singapore's LTA to harvest victim data for SMS code interception, and researchers recommend tracking the kit's file-name signatures to trigger takedowns of new phishing pages.

  • Operated by threat actor ChenLun (Group-IB attribution); generated 100,000+ phishing pages across 54+ countries from December 2025 to May 2026.
  • Operation Ghost Hook in June 2026 (FBI, Google, Lumen's Black Lotus Labs) seized core admin servers, a Shopify storefront, roughly $100,000 and thousands of domains.
  • Despite the takedown, 700+ new phishing pages appeared within a month (described as domains in part of Infosecurity Magazine's report; as pages in its headline and by The Hacker News), per Group-IB findings reported by both outlets.
  • Kit served 267 templates covering finance, telecom, postal, government and toll scams.
  • Adversary-in-the-middle component dynamically served MFA challenges and relayed victim input in real time via WebSockets.
  • SMS delivery ran through a Telegram affiliate ecosystem with more than 5,000 subscribers; The Hacker News cites Telegram as the distribution channel for the post-takedown rebound.
  • Smishing campaign impersonated Singapore's LTA to harvest victim data for SMS code interception.
  • Researchers recommend tracking the kit's file-name signatures to trigger phishing page takedowns.

Coverage timeline

  1. · 12d ago
    Infosecurity Magazine· 57
    Outsider Phishing Kit Survives Takedown With 700 New Pages

    Group-IB found the Outsider phishing kit kept generating 700+ new phishing pages within a month of Operation Ghost Hook's takedown.