Outsider phishing kit survives Ghost Hook takedown

Published September 8, 2026

The Outsider Phishing Kit helps criminals create fake bank, government, postal, and toll websites. It can steal typed details and authentication codes, even when victims leave before submitting the form.

Report priority
Medium

How it works

  • Criminals send text messages impersonating trusted organizations.
  • A link opens a fake website designed to collect payment details, login information, PINs, or authentication codes.
  • The kit passes typed information to the operator during the session.
  • It can also intercept authentication flows and bypass multi-factor authentication.

What to do

Review unexpected texts about tolls, deliveries, payments, or account problems. Treat messages containing links as suspicious, especially when they request payment details, login information, PINs, or authentication codes.

Do not open links in unexpected text messages. Open the organization's official website directly or use its verified mobile application instead.

Technical details

The ChenLun Outsider Phishing-as-a-Service kit uses adversary-in-the-middle techniques to intercept authentication flows. Its scripts send typed information to operators before victims submit forms and can request institution-specific SMS codes, email codes, or PINs.