1/ The @FBICyberDiv and @Google recently announced the takedown of “The Outsider”, a PhaaS platform tied to $1.9B in losses.
We recognized the infrastructure.
We had been tracking the same machine for months, starting from a single phishing SMS.
Here’s what we found 🧵
This week, @FBICleveland, in coordination with Google and Lumen's Black Lotus Labs, conducted a technical takedown operation against Outsider, a Chinese phishing-as-a-service platform (PhaaS) that has been in operation since 2023. The Outsider platform provides cyber criminals with access to infrastructure hosting phishing website files and resources via “phishing kits” and are used to carry out complex phishing attacks against U.S. citizens and companies, as well as victims in at least 54 other countries.
The FBI's investigation revealed that between July 2023 and the present, the Outsider PhaaS platform employed over 8,000 unique phishing domains, accounting for at least an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9B in losses.
Through a joint takedown, the FBI and partners: seized several domains of main admin servers, as well as a Shopify e-commerce storefront and account used to test the phishing service; approximately $100K USDT from Outsider payment wallets; thousands of phishing domains from U.S. providers, rerouting them to an FBI splash page; and leveraged an Outsider Telegram bot to obtain information on Outsider customers.
This action is part of Operation Riptide, an ongoing FBI campaign targeting the criminal actors, infrastructure, and financial networks behind cybercrime, cyber-enabled crime, and fraud against the American people.
Part 2 of our technical teardown of The Outsider is live.
In Part 1, we followed one phishing SMS into the platform’s infrastructure.
In Part 2, we answer the question: how big was the machine?
Part 2 also covers:
- the developer’s failed encryption attempt
- the operator panel
- the fraudster-in-the-loop console
- Cloudflare and Tencent deployment features
- the Telegram ecosystem around the kit
Law enforcement dismantled massive phishing and malware networks, a ransomware cartel abused Microsoft Teams infrastructure, and a state-sponsored group targeted medical research data.
This is the Good, Bad & Ugly. ⬇️
✅ GOOD
- Authorities dismantled Outsider Enterprise, a Chinese PhaaS operation responsible for $1.9 billion in financial losses via fraudulent SMS campaigns.
- Google disabled thousands of associated domains and is actively coordinating with major U.S. carriers to aggressively block malicious text messages.
- Europol and Eurojust successfully removed SocGholish malware infections from nearly 15,000 compromised WordPress websites and dismantled over 100 command servers.
⚠️ BAD
- The DragonForce ransomware operation is utilizing custom malware, Backdoor.Turn, to conceal C2 communications within legitimate Microsoft Teams relay infrastructure.
- Attackers leverage Microsoft’s TURN protocol to establish direct QUIC sessions, remaining undetected by network defenders observing only trusted outbound traffic.
- The threat actors employ extensive BYOVD techniques, systematically deploying vulnerable drivers to achieve kernel-level privileges and actively terminate host security tools.
🤢 UGLY
- PRC-linked espionage group UNC6508 breached legacy REDCap servers to stealthily steal sensitive research from a North American medical institution.
- The attackers deployed the custom "InfiniteRed" malware, which intercepts user logins and receives commands via HTTP cookies to grant extensive execution capabilities.
- Operators uniquely abused legitimate enterprise content compliance features to automatically exfiltrate emails containing specific geo-strategic and molecular discovery keywords.
Full breakdown → https://t.co/LKC2KTetPP
@SentinelOne Unfortunately there are still some "Outsider Enterprise" instances live as of today despite the takedown... We recently mapped this one: the origin sat on Tencent behind Cloudflare, and the platform's own API was leaking operator handles and victim IPs: https://t.co/3M4Gr9DmXe
7/ Part 2 follows next week.
We’ll use the platform’s own leaked telemetry to estimate victim count and revenue, and show how the developer tried to hide the leak after the fact.
New research outfit: @TapetumLabs
Follow for Part 2.
1/ The @FBICyberDiv and @Google recently announced the takedown of “The Outsider”, a PhaaS platform tied to $1.9B in losses.
We recognized the infrastructure.
We had been tracking the same machine for months, starting from a single phishing SMS.
Here’s what we found 🧵
This week, @FBICleveland, in coordination with Google and Lumen's Black Lotus Labs, conducted a technical takedown operation against Outsider, a Chinese phishing-as-a-service platform (PhaaS) that has been in operation since 2023. The Outsider platform provides cyber criminals with access to infrastructure hosting phishing website files and resources via “phishing kits” and are used to carry out complex phishing attacks against U.S. citizens and companies, as well as victims in at least 54 other countries.
The FBI's investigation revealed that between July 2023 and the present, the Outsider PhaaS platform employed over 8,000 unique phishing domains, accounting for at least an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9B in losses.
Through a joint takedown, the FBI and partners: seized several domains of main admin servers, as well as a Shopify e-commerce storefront and account used to test the phishing service; approximately $100K USDT from Outsider payment wallets; thousands of phishing domains from U.S. providers, rerouting them to an FBI splash page; and leveraged an Outsider Telegram bot to obtain information on Outsider customers.
This action is part of Operation Riptide, an ongoing FBI campaign targeting the criminal actors, infrastructure, and financial networks behind cybercrime, cyber-enabled crime, and fraud against the American people.
6/ We’re publishing Part 1 today under @TapetumLabs.
The post includes:
the initial SMS
domain pivots
Cloudflare-to-origin pivoting
backend API findings
reproducible Shodan / Validin / urlscan hunting queries
Full teardown: https://t.co/3M4Gr9DmXe