Skip to main content
Mallory
🇨🇳 CN

Outsider

Also known asoutsider

Outsider is a China-based cybercrime network and phishing-as-a-service operation active since at least July 2023. It provided phishing kits, hosted infrastructure, and related services to cybercriminal customers, facilitating phishing and smishing attacks against people and businesses in 55 countries, including the United States. Authorities estimated the operation caused $1.9 billion in losses, and Google said its activity affected more than 100,000 victims. According to the provided reporting, Outsider operated as a multi-group criminal ecosystem, also referred to as the Outsider Enterprise, composed of interconnected groups with specialized roles and overlapping infrastructure. These included a Developer Group that supplied phishing software and templates, a Data Broker Group that provided target lists, a Spammer Group that sent bulk fraudulent texts, a Theft Group that monetized stolen data and laundered funds, and a Telegram Group that coordinated collaboration and recruitment. Outsider sold phishing kits by subscription for as little as $88 per week, including through a Telegram self-service ordering bot identified as @OutsiderCodeBot. The kits enabled customers to generate fake websites and phishing campaigns impersonating trusted brands, including Google, using more than 290 pre-built templates. Reported lures included missed packages, overdue highway tolls, parking violations, brokerage account issues, and wireless carrier rewards. Google described the operation as AI-enabled or AI-powered, stating that customers were encouraged to use Gemini and other AI platforms to generate custom code for phishing lures and fraudulent sites. The software reportedly supported collection of SMS, PIN, email, and app-based verification data, helping attackers bypass authentication controls, and also included real-time keystroke logging and campaign performance dashboards. The operation relied heavily on Telegram-based infrastructure and large-scale SMS phishing distribution. Google linked Outsider to 9,000 fake websites and more than 1.59 million fraudulent URLs between November 14, 2025 and April 14, 2026, and said 2.5 million messages containing links to Outsider-generated websites were sent to Android users during a two-week period in 2026. The FBI said Outsider phishing domains were linked to nearly 3.9 million stolen credit cards. The network was disrupted by the FBI, Google, and Lumen Technologies in a coordinated action called Operation Ghost Hook, part of the FBI's broader Operation Riptide. The takedown included seizure of core administrative domains, a Shopify storefront, roughly $100,000 from payment wallets, and thousands of domains registered through U.S.-based providers. Google also filed civil litigation to dismantle the group's infrastructure. Known alias/sub-group naming directly mentioned in the content: Outsider Enterprise.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Banks
  • Financial Services
  • Software & Services
  • Telecommunication Services

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

3 of 15 tactics5 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.003
Spearphishing via Service
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1111
Multi-Factor Authentication Interception
TA0009
Collection
1 technique
T1056
Input Capture
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping4

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Outsider | Mallory