
A phishing kit that walks victims through their own MFA prompt survived the takedown
Group-IB counted more than 100,000 pages from one phishing-as-a-service platform, then more than 700 new ones in the month after Google and the FBI moved against it. The part that matters for a small business is what it does with your second factor.
Group-IB published research on 3 September into what it calls the Outsider phishing kit, a phishing-as-a-service platform run by a threat actor known as ChenLun. Between December 2025 and May 2026 the firm identified more than 100,000 phishing pages built with it, aimed at 54 or more countries, drawing on 267 ready-made templates covering financial services, brokerage firms, telecoms providers, postal services, government and toll systems. The pages were delivered by SMS, and the kit was sold and managed through a Telegram ecosystem.
Law enforcement moved against it. Google filed a civil lawsuit on 12 June, and the following day the FBI's Cyber Division announced a coordinated effort with Google and Lumen's Black Lotus Labs called Operation Ghost Hook, which seized the group's core admin servers, a Shopify storefront, around $100,000 from its payment wallets and thousands of domains registered through US providers.
It kept going anyway
Group-IB had linked more than 10,000 unique domains to Outsider before the operation. In the month afterwards it identified more than 700 additional ones, which tells you affiliates carried on using the kit while its infrastructure was being dismantled. That is the pattern to take from this rather than the seizure figures: phishing platforms are rented, not owned, and removing the shopfront does not remove the customers.
What adversary in the middle means in practice
The kit includes adversary-in-the-middle capability, which is the detail worth understanding even if the acronyms are not your job. Instead of a static fake login page collecting a password for later use, the page sits between the victim and whatever the attacker is really logging into, and relays in real time. Group-IB found operators could dynamically serve SMS, email, PIN or app-based multi-factor challenges, and send victims back to earlier pages to ask for more payment details. The kit used WebSockets to keep a live connection between the phishing page and an operator panel, so what a victim typed was passed across as they typed it, including when somebody started filling in a form and abandoned it.
Put simply: a member of your staff can receive the multi-factor prompt they were expecting, on the right phone, at the right moment, approve it, and hand an attacker a working session. The prompt is real. It was triggered by the attacker, using the credentials your colleague had just typed into the fake page.
The lure looked like admin, not a scam
Group-IB examined one campaign impersonating Singapore's Land Transport Authority. The messages built urgency around an alleged data synchronisation problem, and included instructions telling recipients how to get past their own handset's spam filtering. The cloned portal collected vehicle registration numbers and phone numbers before pushing victims to fraudulent payment screens, with the harvested numbers intended for intercepting SMS authentication codes later on. Nothing about falling for that requires carelessness. It is a boring administrative message about a record that needs updating, dealt with on a phone between other jobs.
What to change
First, treat SMS codes and typed one-time passcodes as the weakest form of multi-factor authentication you can run, because both can be relayed live by a kit like this one. Where your systems support them, passkeys and hardware security keys are bound to the real site's address and will not work on a lookalike domain, which closes the specific hole described here. Second, tell your team the thing most security training leaves out: approving a plausible prompt straight after entering your details on a page you reached from a link is how accounts get taken, so the prompt arriving is not proof the site was real. Third, follow Group-IB's own advice for individuals and check any alert through the official app or by typing the address yourself, never through the link in the message.
What this means for your business
Multi-factor authentication is still worth having and this research does not change that. What it changes is the assumption underneath it, because a kit rented by the month can now sit in the middle of a login and pass your staff's code straight through to a real session. For most small businesses the practical response is to move the accounts that matter most, the email tenant and the finance systems, off SMS codes and onto passkeys or security keys, and to make sure staff know that an expected-looking prompt is not evidence the page that triggered it was real. If your team still confirms logins by typing six digits from a text message, that is the change worth booking in this autumn.
#WEARECOBALT
Ready when you are.
Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.