Group-IB found ChenLun’s Outsider phishing-as-a-service kit had generated more than 700 new phishing pages within a month of the Google/FBI disruption known as Operation Ghost Hook. The takedown seized core admin servers, a Shopify storefront, about $100,000 in payment wallets, and thousands of domains, but the campaign kept producing fresh victim-facing pages.
The kit works like a phishing factory: affiliates choose ready-made templates, push SMS lures, and get lookalike pages and domains back from the service. Group-IB said the platform also had adversary-in-the-middle features that could step through SMS, email, PIN, or app-based checks, which means a seized domain set does not end the affiliate pipeline behind it.
For defenders, the lesson is that domain seizures can remove inventory without breaking the machinery that replaces it. If authentication still depends on SMS codes or click-through login links, the durable exposure is the service model and its affiliate ecosystem, not any single page or domain that gets knocked offline.