Outsider Phishing Kit Rebounds With 700+ New Pages Within a Month of Operation Ghost Hook Takedown
Group-IB found the Outsider phishing-as-a-service kit, run by a threat actor tracked as ChenLun, produced 100,000+ phishing pages across 54+ countries from December 2025 to May 2026; after the FBI, Google and Lumen's Black Lotus Labs seized its core admin…
Group-IB linked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, to more than 100,000 phishing pages across 54+ countries between December 2025 and May 2026 (Infosecurity Magazine). In June 2026, Operation Ghost Hook — carried out by the FBI, Google and Lumen's Black Lotus Labs — seized the kit's core admin servers, a Shopify storefront, roughly $100,000 and thousands of domains. Both outlets, citing Group-IB, report the kit nonetheless generated 700+ new phishing pages within a month of the takedown; Infosecurity Magazine's report describes them as new phishing domains in one passage, while its headline and The Hacker News call them phishing pages. The Hacker News adds that the rebound pages were distributed via Telegram. The kit offered 267 templates for finance, telecom, postal, government and toll scams, an adversary-in-the-middle component that dynamically served MFA challenges and relayed victim input in real time over WebSockets, and SMS delivery through a Telegram affiliate ecosystem with more than 5,000 subscribers. Group-IB also documented a smishing campaign impersonating Singapore's LTA to harvest victim data for SMS code interception, and researchers recommend tracking the kit's file-name signatures to trigger takedowns of new phishing pages.
- Operated by threat actor ChenLun (Group-IB attribution); generated 100,000+ phishing pages across 54+ countries from December 2025 to May 2026.
- Operation Ghost Hook in June 2026 (FBI, Google, Lumen's Black Lotus Labs) seized core admin servers, a Shopify storefront, roughly $100,000 and thousands of domains.
- Despite the takedown, 700+ new phishing pages appeared within a month (described as domains in part of Infosecurity Magazine's report; as pages in its headline and by The Hacker News), per Group-IB findings reported by both outlets.
- Kit served 267 templates covering finance, telecom, postal, government and toll scams.
- Adversary-in-the-middle component dynamically served MFA challenges and relayed victim input in real time via WebSockets.
- SMS delivery ran through a Telegram affiliate ecosystem with more than 5,000 subscribers; The Hacker News cites Telegram as the distribution channel for the post-takedown rebound.
- Smishing campaign impersonated Singapore's LTA to harvest victim data for SMS code interception.
- Researchers recommend tracking the kit's file-name signatures to trigger phishing page takedowns.
Coverage timelineoldest first · each row is one article
- · 12d agoOutsider Phishing Kit Survives Takedown With 700 New Pages
Infosecurity Magazine· 57
Group-IB found the Outsider phishing kit kept generating 700+ new phishing pages within a month of Operation Ghost Hook's takedown.