ChenLun is the operator of Outsider, a Phishing-as-a-Service platform also known as 局外人. Outsider supplies affiliates with customizable phishing templates, campaign administration, real-time victim interaction, stolen-data storage, redirect controls, and configurable multi-factor-authentication collection flows. From December 2025 through May 2026, the operation generated more than 100,000 phishing pages targeting victims in at least 54 countries, principally through SMS phishing. Its template library impersonates financial and brokerage services, telecommunications providers, postal and shipping services, government and toll services, and e-commerce and technology brands. Outsider supports adversary-in-the-middle phishing workflows that collect account credentials, payment-card data, personal information, PINs, and SMS-, email-, application-, and PIN-based MFA challenges. The platform can capture victim input before form submission, maintain live communications between victim pages and operator panels, track victim and device activity, and solicit additional payment cards. It also incorporates browser-analysis disruption, bot and security-crawler detection, and test-card filtering. A Singapore-focused campaign impersonated the Land Transport Authority to collect vehicle-registration and telephone data before presenting fraudulent payment workflows; collected phone numbers were intended to facilitate later interception of SMS authentication codes. ChenLun marketed and supported Outsider through a Telegram ecosystem comprising update, affiliate, discussion, sales, and support channels. Law-enforcement and private-sector disruption activity in June 2026 targeted Outsider infrastructure and associated assets, but affiliates continued deploying new phishing pages afterward.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates the Outsider phishing-as-a-service platform. Despite Operation Ghost Hook seizing core infrastructure, affiliates continued deploying the kit, with more than 700 new phishing domains identified after the disruption. The service provides hundreds of phishing templates and supports SMS-delivered campaigns, Telegram-based affiliate management, adversary-in-the-middle phishing, real-time collection of credentials and payment data, and interception of SMS authentication codes.
Operates and markets the Outsider phishing-as-a-service platform to affiliates through a Telegram ecosystem. The service supports large-scale SMS phishing campaigns, real-time credential and payment-card interception, live operator-directed MFA challenges, and adversary-in-the-middle functionality.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.