China-based cybercriminals are using a sophisticated phishing-as-a-service platform called the “Outsider Phishing Kit” to launch massive phishing campaigns around the world, according to researchers at Group-IB.
“The scale of this operation is staggering,” the researchers write. “From December 2025 to May 2026, Group-IB has identified over 100,000 phishing pages targeting 54+ countries, leveraging 267 (and growing) phishing templates. These numbers underscore the increasingly low barrier to entry for threat actors to launch and operate large-scale phishing campaigns.”
Google filed a lawsuit against the group behind the phishing kit in June, and the FBI assisted in a coordinated takedown of its infrastructure. The threat actor has proved persistent, however, and Group-IB observed hundreds of new phishing pages in a single month after the takedown.
- “Phishing page creation: Affiliates can deploy phishing campaigns using a library of 267 pre-built templates, with the ability to customize and modify pages as needed.
- Real-time victim management: Victims interacting with phishing pages can be redirected to attacker-defined endpoints, enabling the collection of credentials, payment information, and other sensitive data.
- Centralized dashboard: The panel provides real-time visibility into campaign activity, including phishing page visits, victim interactions, and harvested data.
- Centralized data storage: Information captured during phishing campaigns is consolidated within the panel, allowing affiliates to review and manage stolen data from a single interface.”
The researchers conclude that users need to be wary of an increasing volume of polished phishing attacks as kits like Outsider lower the bar for cybercriminals.
While these social engineering tactics aren’t new, Microsoft says the phishing campaign stands out due to how it “layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism.”
“The Outsider Phishing Kit represents a significant marker in the evolution of phishing-as-a-service ecosystems,” Group-IB says. “What was once a technically demanding operation has been reduced to a subscription and a Telegram channel. Despite law enforcement and platform takedown efforts through Operation Ghost Hook, affiliates continue to actively use the kit and create new campaigns. Organizations and individuals must remain vigilant as the threat persists.”
Group IB has the story: https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/
