Outsider Enterprise is a China-based cybercrime network operating a phishing-as-a-service ecosystem centered on large-scale SMS phishing and credential and payment-card theft. The group coordinates openly through Telegram and provides turnkey phishing kits, training, and operational support to other criminals, lowering the barrier to entry for fraud campaigns. Its platform has been described as offering more than 290 prebuilt templates that impersonate trusted brands and institutions, including technology companies, financial institutions, telecom providers, delivery services, toll systems, and government entities. The group’s operations are associated with mass smishing campaigns that direct victims to fraudulent websites designed to capture passwords, payment-card data, multi-factor authentication codes, PINs, and other personal or financial information. Victim data is reportedly collected in real time through the platform. Outsider Enterprise has also been linked to the use of artificial intelligence tools, including Gemini, to accelerate the creation of phishing pages and scam infrastructure by generating custom HTML and related content that can be imported into its phishing kits. The enterprise functions as an organized criminal service model rather than a single isolated operator, with roles reportedly spanning developers, spam distributors, target-list suppliers, and actors involved in monetizing stolen data and laundering proceeds. It has been tied to thousands of phishing websites, more than one million fraudulent URLs, millions of scam text messages, and victims across dozens of countries since at least 2023. Public reporting attributes to the operation large-scale theft of payment-card data and substantial financial losses. Its dominant activity profile is financially motivated cyber-enabled fraud rather than espionage or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service group operating via Telegram that allegedly used Google Gemini to help create phishing websites impersonating Google, YouTube, and government agencies, and offered hundreds of scam templates.
Mentioned only in a related-content link about a phishing service; not part of the Chrome vulnerability article itself.
Large-scale phishing-as-a-service operation distributing phishing kits, fake websites, and scam text campaigns impersonating trusted brands to steal credentials, payment card data, and personal information.
China-based phishing-as-a-service operation selling phishing kits via Telegram, enabling customers to rapidly deploy fake bank, toll, delivery, carrier, government, DMV, USPS, and E-ZPass-themed phishing pages to steal payment card data and multi-factor authentication codes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.