Outsider is a China-linked cybercrime enterprise operating a phishing-as-a-service ecosystem centered on large-scale SMS phishing and brand impersonation. The operation has been described as a multi-group criminal network with specialized roles including phishing-kit development, target-data brokerage, bulk message delivery, monetization of stolen data, and Telegram-based coordination and recruitment. Outsider has offered phishing kits and hosted infrastructure since at least July 2023 and enabled attacks against individuals and businesses across dozens of countries. The group’s activity is focused on smishing campaigns that impersonate trusted brands, telecom providers, government services, financial themes, and commercial entities to lure victims into fraudulent websites. These campaigns have used prebuilt phishing templates and hosted landing pages to steal payment card data, bank credentials, account information, and other personal data. Reported lures have included package-delivery issues, toll or parking notices, account warnings, brokerage-related prompts, and rewards-themed messages. Outsider’s tooling has also been reported to support collection of one-time codes and other verification inputs, improving the operators’ ability to bypass authentication workflows. Outsider has been characterized as AI-enabled rather than AI-native: operators and customers allegedly used Gemini and other AI tools to generate or refine phishing-page code, localized lure text, and other campaign content at scale. This use of AI appears to have increased the speed, volume, and adaptability of phishing operations rather than changing the underlying tradecraft. The service reportedly included hundreds of phishing templates, campaign tracking features, and real-time keystroke logging, and was marketed through Telegram-based self-service mechanisms on a subscription basis. The enterprise has been linked to widespread victimization, substantial financial losses, and infrastructure at significant scale, including thousands of phishing websites and mass delivery of fraudulent text messages. Authorities and industry defenders have attributed the operation to actors based in China and have undertaken coordinated disruption efforts involving domain seizures, financial seizures, litigation, and telecom cooperation. Known aliases directly supported at high confidence are limited to Outsider; reporting also refers to the broader operation as the Outsider Enterprise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Large-scale SMS phishing and scam infrastructure operation using AI tools to generate and support fake websites impersonating telecom companies, government services, and commercial brands in order to steal payment card details, credentials, and personal information.
China-based phishing-as-a-service cybercrime operation providing phishing kits, hosted infrastructure, and AI-assisted tooling to enable large-scale credential theft and payment card fraud against victims in dozens of countries.
Chinese cybercrime network accused of developing and managing the Outsider phishing-as-a-service kit and conducting large-scale SMS phishing campaigns impersonating trusted brands to steal personal and financial information from Americans.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.