{"investigation":{"slug":"outsider-enterprise","entity_name":"Outsider Enterprise","trust_score":2,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Outsider Enterprise is a China-based phishing-as-a-service operation, attributed by researchers to a threat actor known as ChenLun, that sold subscription-based phishing kits through a Telegram bot since at least July 2023. On June 12, 2026, Google filed a civil RICO and Lanham Act lawsuit against 25 Doe defendants (case No. 1:26-cv-04982-VM, S.D.N.Y.), and the FBI announced Operation Ghost Hook the following day, seizing domains and approximately $100,000 from the operation's payment wallets. The FBI's Cyber Division has linked the platform to an estimated $1.9 billion in losses and approximately 3.87 million compromised payment card numbers; post-takedown research published September 3, 2026 found the affiliate network remained active with over 700 new phishing domains identified after the enforcement action.","sections":[{"content":"Outsider Enterprise, also rendered in Chinese as 局外人 ('Outsider'), is a phishing-as-a-service (PhaaS) platform that has operated since at least July 2023. The service is attributed by cybersecurity firm Group-IB to a threat actor identified by the online handle 'ChenLun.' The platform is coordinated primarily through Telegram and structured as a subscription service, with kit access sold for as little as $88 per week or approximately $200 per month via a dedicated Telegram bot (@OutsiderCodeBot), which became inaccessible following the June 2026 enforcement actions. The Outsider kit is designed to lower the technical barrier for criminal actors: subscribers receive access to over 267 to 290 pre-built phishing page templates across multiple industry categories, real-time keystroke logging infrastructure, a performance dashboard, and step-by-step tutorials instructing users on how to generate custom phishing page HTML using Google's Gemini AI and other AI tools. According to Google's complaint, the service also included adversary-in-the-middle (AiTM) capabilities enabling interception of multi-factor authentication tokens in real time. Before the June 2026 takedown, the Outsider Telegram channel had an estimated 5,000+ subscribers, with approximately 230 active kit purchasers.","heading":"Background and Overview","sources":[{"url":"https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/","name":"Group-IB: The Outsider Phishing Kit — A Resilient Threat in the Face of Law Enforcement Action","type":"research","credibility":2},{"url":"https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/","name":"CyberScoop: FBI takes down massive China-based cybercrime network","type":"news_article","credibility":2},{"url":"https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html","name":"The Hacker News: Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing","type":"news_article","credibility":2}],"severity":"critical"},{"content":"On June 12, 2026, Google's General Counsel Halimah DeLaine Prado announced the filing of a civil complaint in the U.S. District Court for the Southern District of New York (case No. 1:26-cv-04982-VM) against 25 unnamed Doe defendants identified collectively as the 'Outsider Enterprise.' The complaint is reported to allege violations of the Racketeer Influenced and Corrupt Organizations Act (RICO) under 18 U.S.C. § 1962(c) and conspiracy under § 1962(d), with wire fraud as a predicate act. The complaint also alleges Lanham Act claims including trademark infringement (15 U.S.C. § 1114(1)), false association, and false advertising, with Google asserting that at least 14 Outsider templates misuse Google trademarks including Google Pay, Google Play, and YouTube. Additional claims include copyright infringement and misuse of Google Cloud and Drive services. Google seeks injunctive relief to dismantle the operation's infrastructure. The complaint describes five interlocking groups constituting the criminal enterprise: a Developer Group (building phishing software and templates), a Data Broker Group (supplying target victim lists), a Spammer Group (operating bulk SMS delivery tools), a Theft Group (monetizing stolen credentials and payment data), and a Telegram Group (handling coordination, sales, training, and recruitment). No individuals have been publicly named as defendants; all 25 are identified only as Doe defendants alleged to be China-based. As of September 2026, the case remains at an early stage with no public ruling on the merits.","heading":"Legal Action: Google Civil Lawsuit (RICO and Lanham Act)","sources":[{"url":"https://securityboulevard.com/2026/07/google-sues-chinese-ai-phishing-phactory/","name":"Security Boulevard: Google Sues Chinese AI Phishing Phactory","type":"news_article","credibility":2},{"url":"https://cryptobriefing.com/google-ai-phishing-lawsuit-outsider-enterprise/","name":"Crypto Briefing: Google's Landmark AI Phishing Lawsuit","type":"news_article","credibility":2},{"url":"https://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/","name":"TechCrunch: Chinese cybercrime operation that used AI to scam hundreds of thousands of victims sued by Google","type":"news_article","credibility":1},{"url":"https://www.securityweek.com/fbi-google-dismantle-outsider-enterprise-phishing-service/","name":"SecurityWeek: FBI, Google Dismantle 'Outsider Enterprise' Phishing Service","type":"news_article","credibility":2}],"severity":"critical"},{"content":"On June 13, 2026, the FBI's Cyber Division announced a coordinated technical takedown designated Operation Ghost Hook, conducted jointly with Google and Lumen Technologies' Black Lotus Labs. The operation resulted in the seizure of several core administrative server domains, a Shopify storefront used for kit testing and distribution, approximately $100,000 from the operation's payment wallets, and thousands of phishing domains registered through U.S.-based domain providers, which were rerouted to an FBI notice page. FBI Cyber Division Assistant Director Brett Leatherman stated: 'The criminals behind Outsider Enterprise built a business out of impersonating trusted brands to defraud hundreds of thousands of victims.' Operation Ghost Hook is described as part of a broader ongoing FBI campaign called Operation Riptide, which targets the masterminds, infrastructure, and financial networks behind cybercrime organizations. The FBI also reported using access to Outsider's Telegram bot to gather intelligence on the network's customers during the investigation.","heading":"FBI Operation Ghost Hook","sources":[{"url":"https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/","name":"CyberScoop: FBI takes down massive China-based cybercrime network","type":"news_article","credibility":2},{"url":"https://www.tomshardware.com/tech-industry/cyber-security/fbi-and-google-dismantle-chinese-phishing-service-that-coached-buyers-to-generate-scam-sites-with-gemini","name":"Tom's Hardware: FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI","type":"news_article","credibility":2},{"url":"https://www.heise.de/en/news/FBI-takes-down-Phishing-as-a-Service-platform-Outsider-11334318.html","name":"Heise Online: FBI takes down Phishing-as-a-Service platform Outsider","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The FBI's Cyber Division has linked the Outsider platform to an estimated $1.9 billion in victim losses dating back to July 2023, and approximately 3.87 million compromised payment card numbers. Between November 2025 and April 2026, the operation is associated with over 1.59 million malicious URLs, and in a single two-week period in May 2026 (May 18–June 1), an estimated 2.5 million fraudulent SMS messages were sent to Android users in the United States, with Android's spam-detection systems flagging over 55,000 of those texts. Group-IB identified over 100,000 phishing pages associated with the Outsider kit between December 2025 and May 2026 across 54 or more countries, and Google's complaint identifies over 9,000 fake websites built using the kit. The platform operated 290+ pre-built templates, of which 131 were specifically designed to target U.S. victims; impersonated entities include banks, telecom providers, government agencies, shipping companies, and retailers. On a single day captured in Google's complaint evidence, 62,993 new phishing pages were detected. The FBI has estimated that the platform served hundreds of thousands of victims across 55 countries.","heading":"Scale and Estimated Harm","sources":[{"url":"https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/","name":"CyberScoop: FBI takes down massive China-based cybercrime network","type":"news_article","credibility":2},{"url":"https://www.securityweek.com/fbi-google-dismantle-outsider-enterprise-phishing-service/","name":"SecurityWeek: FBI, Google Dismantle 'Outsider Enterprise' Phishing Service","type":"news_article","credibility":2},{"url":"https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/","name":"Group-IB: The Outsider Phishing Kit — A Resilient Threat","type":"research","credibility":2}],"severity":"critical"},{"content":"Google's complaint specifically alleges that Outsider operators distributed tutorials instructing subscribers how to prompt Google's Gemini AI to generate HTML code for convincing phishing pages. The technique involved framing requests as benign tasks, for example asking Gemini to generate HTML for a 'gift redemption page' with specific functional requirements while instructing it to avoid JavaScript and use inline CSS. The resulting code could then be copied directly into the Outsider kit to produce credential-harvesting pages. Cryptobriefing reported this as the first U.S. lawsuit to explicitly target the misuse of Google's own AI platform for phishing operations. Google's complaint notes that the AI-generated code itself is not inherently malicious; the criminal application occurs when it is combined with the Outsider platform's backend harvesting and exfiltration infrastructure. The complaint also alleges misuse of Google Cloud and Google Drive services as part of the operation's hosting and delivery infrastructure.","heading":"AI Misuse: Gemini-Assisted Phishing Page Generation","sources":[{"url":"https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html","name":"The Hacker News: Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing","type":"news_article","credibility":2},{"url":"https://cryptobriefing.com/google-ai-phishing-lawsuit-outsider-enterprise/","name":"Crypto Briefing: Google AI Phishing Lawsuit — Outsider Enterprise","type":"news_article","credibility":2},{"url":"https://securityboulevard.com/2026/07/google-sues-chinese-ai-phishing-phactory/","name":"Security Boulevard: Google Sues Chinese AI Phishing Phactory","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Outsider Enterprise's 267 to 290 pre-built templates spanned eight primary categories including financial services, telecommunications, postal and shipping, and government agencies. According to Group-IB's September 2026 analysis, targeted institutions include banks, brokerages, and financial platforms. The platform's technical infrastructure includes real-time keystroke logging using AES-256-CTR encryption, WebSocket-based command-and-control communications enabling live operator manipulation of multi-factor authentication challenges, and a GetSyncSettings configuration profile managing victim flow, card rejection triggers, and multi-card harvesting. This architecture was specifically designed to harvest not only payment card numbers but also banking login credentials, brokerage credentials, and two-factor authentication tokens in real time. The context provided by Google's complaint and affiliated researchers indicates that phishing pages targeted financial credential holders broadly; the initial claim that the operation explicitly targeted cryptocurrency wallet and exchange logins specifically has not been independently verified in Tier 1 or Tier 2 source material reviewed for this investigation — verified targeting appears centered on financial services, brokerages, telecom, government, and logistics rather than crypto-native infrastructure specifically. Readers should weigh the crypto-targeting framing accordingly.","heading":"Financial Services and Brokerage Credential Targeting","sources":[{"url":"https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/","name":"Group-IB: The Outsider Phishing Kit — A Resilient Threat","type":"research","credibility":2},{"url":"https://www.securityweek.com/fbi-google-dismantle-outsider-enterprise-phishing-service/","name":"SecurityWeek: FBI, Google Dismantle 'Outsider Enterprise' Phishing Service","type":"news_article","credibility":2}],"severity":"high"},{"content":"Research published on September 3, 2026 by Group-IB found that despite Operation Ghost Hook's seizure of core infrastructure, the Outsider affiliate network remained active. Group-IB, which had linked more than 10,000 unique domains to Outsider before the takedown, identified over 700 additional domains created within approximately one month after the June 12 enforcement actions. The primary Telegram channel operated by ChenLun for kit sales and affiliate management was deleted following the takedown; however, individual affiliates who had already obtained the kit continued deploying phishing campaigns independently using the previously distributed templates and infrastructure. The Infosecurity Magazine report characterizing this persistence was published September 3, 2026 and represents the most recent information available as of the date of this investigation.","heading":"Post-Takedown Resilience","sources":[{"url":"https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/","name":"Infosecurity Magazine: Outsider Phishing Kit Survives Takedown With 700 New Pages","type":"news_article","credibility":2},{"url":"https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/","name":"Group-IB: The Outsider Phishing Kit — A Resilient Threat","type":"research","credibility":2}],"severity":"high"},{"content":"Google coordinated the enforcement action with AT&T, T-Mobile, and Verizon to block Outsider-generated phishing SMS messages at the carrier level. Google's General Counsel Halimah DeLaine Prado used the announcement to advocate for seven bipartisan congressional bills addressing cyber-enabled fraud and scam prevention, framing the lawsuit as part of a broader policy effort. The Cryptobriefing analysis noted that if Google's RICO theory prevails, it could establish a legal precedent treating AI-assisted phishing operations as sophisticated criminal enterprises under federal racketeering law rather than individual opportunistic actors, potentially affecting how future prosecutions are structured. The case is also described as the first U.S. lawsuit to explicitly target misuse of a major AI platform's own product in the commission of large-scale phishing.","heading":"Industry and Legislative Response","sources":[{"url":"https://cryptobriefing.com/google-ai-phishing-lawsuit-outsider-enterprise/","name":"Crypto Briefing: Google AI Phishing Lawsuit — Outsider Enterprise","type":"news_article","credibility":2},{"url":"https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/","name":"CyberScoop: FBI takes down massive China-based cybercrime network","type":"news_article","credibility":2}],"severity":"medium"},{"content":"All 25 defendants named in Google's civil complaint are identified only as Does 1–25. No individual defendants have been publicly named in connection with either the civil lawsuit or the FBI's Operation Ghost Hook as of September 2026. The operator of the Outsider Telegram infrastructure is attributed by Group-IB to a threat actor using the handle 'ChenLun,' with Group-IB reporting high confidence in this attribution based on Telegram channel activity analysis. The operation is described as China-based by multiple sources including Google's complaint and FBI statements, but no specific location within China has been publicly identified, and no arrests or criminal indictments had been publicly announced as of the date of this investigation. Readers should note that all characterizations of individual culpability in this matter remain at the allegation stage; no court has made findings on the merits.","heading":"Defendant Identification and Attribution","sources":[{"url":"https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/","name":"Group-IB: The Outsider Phishing Kit — A Resilient Threat","type":"research","credibility":2},{"url":"https://www.securityweek.com/fbi-google-dismantle-outsider-enterprise-phishing-service/","name":"SecurityWeek: FBI, Google Dismantle 'Outsider Enterprise' Phishing Service","type":"news_article","credibility":2},{"url":"https://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/","name":"TechCrunch: Chinese cybercrime operation sued by Google","type":"news_article","credibility":1}],"severity":"medium"}],"timeline":[{"date":"2023-07-01","event":"Outsider Enterprise phishing-as-a-service platform begins operating, per FBI Cyber Division attribution linking losses to this date.","source":"CyberScoop / FBI statement","source_url":"https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/"},{"date":"2025-12-01","event":"Group-IB begins tracking Outsider phishing pages at scale; over 100,000 phishing pages identified between December 2025 and May 2026 across 54+ countries.","source":"Group-IB Blog","source_url":"https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/"},{"date":"2026-05-18","event":"Two-week period begins (May 18–June 1) during which Google data shows 2.5 million fraudulent SMS messages sent to Android users; 55,000 flagged as spam.","source":"The Hacker News / Google complaint data","source_url":"https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html"},{"date":"2026-06-12","event":"Google files civil RICO and Lanham Act lawsuit against 25 Doe defendants (case No. 1:26-cv-04982-VM) in the Southern District of New York. Google General Counsel Halimah DeLaine Prado announces the action publicly.","source":"TechCrunch / SecurityWeek","source_url":"https://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/"},{"date":"2026-06-13","event":"FBI Cyber Division announces Operation Ghost Hook, seizing Outsider's core admin server domains, a Shopify storefront, approximately $100,000 from payment wallets, and thousands of phishing domains through U.S. providers. Action conducted jointly with Google and Lumen Technologies' Black Lotus Labs.","source":"CyberScoop / SecurityWeek","source_url":"https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/"},{"date":"2026-06-13","event":"Outsider Telegram bot (@OutsiderCodeBot) becomes inaccessible following enforcement actions. ChenLun deletes the primary Telegram channel.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html"},{"date":"2026-09-03","event":"Group-IB publishes research finding that over 700 new phishing domains associated with the Outsider kit have been created since the June takedown, indicating the affiliate network remained operational despite loss of central infrastructure.","source":"Infosecurity Magazine / Group-IB","source_url":"https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/"}],"sources_used":[{"url":"https://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/","name":"TechCrunch: Chinese cybercrime operation that used AI to scam hundreds of thousands of victims sued by Google","type":"news_article","archive_url":"http://web.archive.org/web/20260723224405/https://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/","credibility":1,"archive_timestamp":"2026-07-23T22:44:05+00:00"},{"url":"https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/","name":"CyberScoop: FBI takes down massive China-based cybercrime network that caused $1.9B in losses","type":"news_article","archive_url":"https://web.archive.org/web/20260915130234/https://cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/","credibility":2,"archive_timestamp":"2026-09-15T13:02:34+00:00"},{"url":"https://www.securityweek.com/fbi-google-dismantle-outsider-enterprise-phishing-service/","name":"SecurityWeek: FBI, Google Dismantle 'Outsider Enterprise' Phishing Service","type":"news_article","archive_url":"https://web.archive.org/web/20260915130745/https://www.securityweek.com/fbi-google-dismantle-outsider-enterprise-phishing-service/","credibility":2,"archive_timestamp":"2026-09-15T13:07:45+00:00"},{"url":"https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html","name":"The Hacker News: Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing","type":"news_article","archive_url":"http://web.archive.org/web/20260904133909/https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html","credibility":2,"archive_timestamp":"2026-09-04T13:39:09+00:00"},{"url":"https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/","name":"Group-IB: The Outsider Phishing Kit — A Resilient Threat in the Face of Law Enforcement Action","type":"research","archive_url":"http://web.archive.org/web/20260910091125/https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/","credibility":2,"archive_timestamp":"2026-09-10T09:11:25+00:00"},{"url":"https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/","name":"Infosecurity Magazine: Outsider Phishing Kit Survives Takedown With 700 New Pages","type":"news_article","archive_url":"http://web.archive.org/web/20260906090400/https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/","credibility":2,"archive_timestamp":"2026-09-06T09:04:00+00:00"},{"url":"https://securityboulevard.com/2026/07/google-sues-chinese-ai-phishing-phactory/","name":"Security Boulevard: Google Sues Chinese AI Phishing Phactory","type":"news_article","archive_url":"http://web.archive.org/web/20260723024126/https://securityboulevard.com/2026/07/google-sues-chinese-ai-phishing-phactory/","credibility":2,"archive_timestamp":"2026-07-23T02:41:26+00:00"},{"url":"https://cryptobriefing.com/google-ai-phishing-lawsuit-outsider-enterprise/","name":"Crypto Briefing: Google AI Phishing Lawsuit — Outsider Enterprise","type":"news_article","archive_url":"https://web.archive.org/web/20260915130132/https://cryptobriefing.com/google-ai-phishing-lawsuit-outsider-enterprise/","credibility":2,"archive_timestamp":"2026-09-15T13:01:32+00:00"},{"url":"https://www.tomshardware.com/tech-industry/cyber-security/fbi-and-google-dismantle-chinese-phishing-service-that-coached-buyers-to-generate-scam-sites-with-gemini","name":"Tom's Hardware: FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI","type":"news_article","archive_url":"http://web.archive.org/web/20260713134035/https://www.tomshardware.com/tech-industry/cyber-security/fbi-and-google-dismantle-chinese-phishing-service-that-coached-buyers-to-generate-scam-sites-with-gemini","credibility":2,"archive_timestamp":"2026-07-13T13:40:35+00:00"},{"url":"https://www.heise.de/en/news/FBI-takes-down-Phishing-as-a-Service-platform-Outsider-11334318.html","name":"Heise Online: FBI takes down Phishing-as-a-Service platform Outsider","type":"news_article","archive_url":"https://web.archive.org/web/20260915130610/https://www.heise.de/en/news/FBI-takes-down-Phishing-as-a-Service-platform-Outsider-11334318.html","credibility":2,"archive_timestamp":"2026-09-15T13:06:10+00:00"},{"url":"https://www.cryptopolitan.com/google-sues-chinese-ai-phishing-ring-outsider-enterprise/","name":"Cryptopolitan: Google sues Chinese AI phishing ring as FBI seizes domains and $100,000 in Operation Ghost Hook","type":"news_article","archive_url":"https://web.archive.org/web/20260916001013/https://www.cryptopolitan.com/google-sues-chinese-ai-phishing-ring-outsider-enterprise/","credibility":2,"archive_timestamp":"2026-09-16T00:10:13+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-15T12:04:24.689668+00:00","updated_at":"2026-09-16T00:12:20.654894+00:00"}}