Security1 distinct publisher3 min readPublished
Group-IB says the phishing kit Google sued over in June kept producing pages after the FBI seized its admin servers and wallets, which puts the durable detection signal in the kit's file names rather than its hosts.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Ten thousand domains carried more than 100,000 pages before June, which averages out to about ten pages per domain [1][6][3]. Apply that density to the 700-plus domains Group-IB counted afterwards and roughly 7,000 pages were back in service inside a month [7][3]. Treat the estimate as soft, because the source is inconsistent about units: the write-up's opening line calls the 700 new phishing pages, its body calls them additional domains [8][7]. Both readings land in the same place. Affiliates were publishing again while the seizure was still weeks old.
Operation Ghost Hook removed the operator's central plumbing, which the FBI described as core admin servers, a Shopify storefront, about $100,000 in payment wallets and thousands of domains registered through US providers [5]. The kit itself remained in place, held by more than 230 buyers on their own infrastructure [11]. Divide the seized wallet balance by that buyer count and you get about $435 a head [4]. Replacement domains cost less than that.
ChenLun then deleted the Telegram channel that had carried more than 5,000 subscribers and served as the affiliate market [11][10]. That reads as a move against researchers rather than a loss of capability. Each buyer already holds a copy of 267 templates spanning financial services, brokerages, telecoms, postal services, government and toll systems [9].
The kit is operator-attended, not a static credential dump. WebSockets carry victim input to an operator panel in real time, including data typed into a form the victim then abandoned [15]. From that panel, operators can serve SMS, email, PIN or app-based multifactor challenges on demand and push victims back to earlier pages to request more payment detail [14]. In the Singapore Land Transport Authority campaign Group-IB examined, the cloned portal took vehicle registration and phone numbers before the fake payment screen, and Group-IB assessed those numbers were collected to intercept SMS authentication codes in a later stage [13]. The lure also told recipients how to switch off their own handset spam filtering [12].
The one artifact that costs an affiliate something to change is the file naming. Pages use a consistent convention with an alphabetical prefix marking the victim's position in the flow, and Group-IB's recommendation is to hunt on those file-name signatures to trigger takedowns [17]. At $435-per-buyer economics, domains are cheap to replace; the template tree is harder to change, since altering it means reworking the panel that reads it.
One caveat on the count. The 700 figure is a one-month snapshot, and publication came on 3 September, about twelve weeks after the 13 June announcement [2][4][5]. The current number is unpublished, and the only ceiling on it is the 10,000 domains the kit ran before the seizure [6].
Ranked by verification strength, evidence, and original report placement.
Group-IB researchers tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, and identified more than 100,000 phishing pages targeting 54 or more countries between December 2025 and May 2026.
Group-IB published the Outsider research on September 3.
Google filed a civil lawsuit against the group on June 12.
The FBI's Cyber Division announced a coordinated effort with Google and Lumen's Black Lotus Labs, dubbed Operation Ghost Hook, on the day after Google's June 12 lawsuit filing.
The FBI said the operation seized the group's core admin servers, a Shopify storefront, about $100,000 from its payment wallets and thousands of domains registered through US providers.
Group-IB had linked more than 10,000 unique domains to Outsider before Operation Ghost Hook.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Vishing gets a product tier: Okta finds kits that steer the victim's browser mid-call1 distinct publisher
security
Passkey enrollment becomes a persistence trick: $10,000 kit outlives the password reset3 distinct publishers
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, one vendor, no primary documents
Every number in this story — the 100,000 pages, the 10,000 domains, the 700 that came after, even what the FBI says it seized — reaches the reader through a single Group-IB report relayed by a single publication. No filing, no bureau statement, no second telemetry source appears. The technical findings are specific enough to be checkable in principle, which is a point in their favour; the headline finding is undercut by the report's own inconsistency about whether 700 refers to pages or to domains.
The criminal uptake is the best-documented part
Unusually for a threat report, the uptake side is quantified from several angles at once: 230-plus paying buyers, 5,000-plus subscribers to the sales channel, 267 templates, 100,000-plus pages across 54 or more countries, and then 700-plus domains rebuilt after the servers went. Those numbers hang together — a kit with hundreds of independent customers is exactly the kind of thing that survives losing its admin panel. What holds the score down is that one vendor produced all of them.
Broadly aligned; the slippage is at the headline
The prose is restrained and numerate, and the framing that the kit outlasted the takedown is supported by the count in front of it. Two things nudge the needle positive: a vendor's tally is the sole basis for grading a federal operation, and the same vendor's closing advice happens to describe its own line of business. Curiously, the headline errs downward — calling 700 rebuilt hosts 700 pages makes the rebuild sound roughly a tenth of the size the body implies.
The research ends where the vendor's catalogue begins
Group-IB is a commercial threat-intelligence firm, and the conclusion a reader is led to — takedowns decay, so you need continuous brand-abuse monitoring and file-name-signature hunting to trigger takedowns — maps onto services it sells. That does not make the file-naming finding less useful; it is the most concretely actionable thing in the story. But the counterweights are absent: Google, the FBI and Lumen have obvious reasons to argue their June operation landed harder than this account allows, and none of them was asked.
Internally coherent, externally unchecked
The chronology is tight and self-consistent — June 12 filing, June 13 announcement, September 3 publication — and the technical detail reads like it came from looking at code rather than from a press release. Against that: a lone publisher, a lone researcher, an unresolved units problem in the load number, and no way from this reporting to tell whether the seized infrastructure stayed down. Enough to act on defensively, not enough to quote as settled.