Skip to main content
Mallory
Malware

Outsider

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

3 techniques
T1583.001DomainsEvidence2

The group deployed 9,000 fake websites, one million fraudulent web domains, and 2.5 million texts sent to Android users in a two-week period, according to Google.

T1584.005BotnetEvidence1

The cybercriminals have allegedly used Google Drive and Google Cloud infrastructure to host the phishing websites.

T1587.001MalwareEvidence2

This group “built, maintains, and uses a turn-key, online software suite that enables criminals, regardless of technical skill, to publish fraudulent websites designed to rob victims and enrich themselves,” according to the complaint.

Initial Access

3 techniques
T1566PhishingEvidence3

Google says uses AI in its campaigns to send scam text messages impersonating Google and other brands to steal passwords and credit card numbers.

T1566.002Spearphishing LinkEvidence2

Its associates are tasked with sending the malicious web link to potential victims via Apple iMessage, Google Messages and other modern messaging methods... Google's cybercrime investigation team said it found 2.6 million messages sent via Google Messages containing links to the phishing group's websites.

T1566.003Spearphishing via ServiceEvidence2

To lure people to the fake websites, the cybercriminals collaborate with one another to send victims malicious text messages, or purchase ads.

Stealth

1 technique
T1036MasqueradingEvidence2

Outsider offers more than 290 pre-built templates that mimic the legitimate websites of financial services providers, phone service providers, government agencies and retailers.

Credential Access

3 techniques
T1056Input CaptureEvidence3

To bypass multifactor authentication, these phishing sites display fake MFA pages that prompt users to get authentication codes. Attackers use the stolen credentials to log into the victim's account in real time, trigger an MFA code from the legitimate institution and then trick the user into providing that code to the fake site.

T1056.001KeyloggingEvidence1

The service also offers more than 290 pre-built templates that impersonate legitimate websites of trusted institutions, real-time keystroke logging, and a performance dashboard to track the effectiveness of a campaign.

T1557Adversary-in-the-MiddleEvidence1

Attackers use the stolen credentials to log into the victim's account in real time, trigger an MFA code from the legitimate institution and then trick the user into providing that code to the fake site.

Collection

3 techniques
T1056Input CaptureEvidence3

To bypass multifactor authentication, these phishing sites display fake MFA pages that prompt users to get authentication codes. Attackers use the stolen credentials to log into the victim's account in real time, trigger an MFA code from the legitimate institution and then trick the user into providing that code to the fake site.

T1056.001KeyloggingEvidence1

The service also offers more than 290 pre-built templates that impersonate legitimate websites of trusted institutions, real-time keystroke logging, and a performance dashboard to track the effectiveness of a campaign.

T1557Adversary-in-the-MiddleEvidence1

Attackers use the stolen credentials to log into the victim's account in real time, trigger an MFA code from the legitimate institution and then trick the user into providing that code to the fake site.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.