In June, Google sued the operators behind Outsider, a phishing-as-a-service kit tied to a threat actor known as ChenLun, and the FBI’s Cyber Division opened Operation Ghost Hook the very next day to dismantle it. Servers seized. A Shopify storefront tied to the operation taken down. Roughly $100,000 pulled from its payment wallets. Thousands of domains registered through US providers handed over. On paper, that is exactly what a phishing takedown is supposed to look like. Group-IB’s research, published September 3, found what actually happened next: more than 700 new phishing domains, built by affiliates who never lost access to the kit itself.
A Kit Built to Outlive Its Own Seller
Before the takedown, Outsider was already operating at industrial scale. Group-IB tracked more than 100,000 phishing pages across 54 or more countries between December 2025 and May 2026, built from a library of 267 templates impersonating banks, shipping carriers, and major online brands. Google separately detected more than 1.5 million phishing URLs tied to the kit between November 2025 and April 2026, and had linked more than 10,000 unique domains to it before Operation Ghost Hook began.
The kit’s real product was never a single website. It was a subscription. ChenLun distributed Outsider through a Telegram ecosystem: an announcement channel for updates, a subscriber-only group for affiliates who had paid for access, a public discussion group, and a bot that handled purchases and answered questions automatically. Each affiliate rented the software, generated their own phishing pages from the template library, and registered their own domains. The seller built the tooling. Thousands of independent operators supplied the infrastructure.
Outsider also carries adversary-in-the-middle, or AiTM, capability. It can sit between a victim and the real login flow, dynamically serving whichever multi-factor authentication challenge that victim’s account actually uses, whether that arrives as an SMS code, an email one-time passcode, a PIN, or an authenticator app prompt, and it can redirect victims back to earlier steps to request additional payment card details. That is what makes the kit valuable enough to survive a federal takedown: it does not just steal a password, it captures the second factor at the exact moment a real one is issued.
What Operation Ghost Hook Actually Removed
The FBI’s action targeted everything a law enforcement seizure is built to reach: centralized servers, a commerce storefront, a pool of money, and domains registered through providers subject to US legal process. Every one of those is a chokepoint that exists once, in one place, under one entity’s control.
None of that touches the part of the business that generates new phishing domains. Every affiliate who had already paid for access still had the software, the templates, and the Telegram channel telling them the kit was still active. Group-IB’s September findings show exactly what that meant in practice: over 700 additional domains registered and put into use after the seizure, run by affiliates who were never named in the lawsuit and whose accounts were never touched by Operation Ghost Hook. The seller’s infrastructure went down. The affiliate network did not.
Why DMARC Never Had a Domain to Protect Here
It is worth being precise about what DMARC does and does not cover in a case like this, because the two are easy to blur. DMARC protects a domain’s own name from being forged in the From header of an email. If an attacker tries to send mail claiming to be from your domain, and your domain enforces DMARC at p=reject, that message gets rejected before it reaches an inbox.
That is not what Outsider’s 700 new domains are doing. These are not forged versions of a bank’s or carrier’s actual sending domain. They are brand-new domains the affiliates registered themselves, standing in as the landing page a victim is lured toward, typically by SMS, though the same templates and the same AiTM engine work identically behind a link delivered by email. DMARC has no jurisdiction over a domain nobody is impersonating in a From header. It cannot flag a freshly registered lookalike domain as suspicious, and it has nothing to say about what that domain’s login page does to the multi-factor code a victim types into it. That entire chain, from the lure to the credential capture to the real-time MFA relay, happens in the layer past the one DMARC inspects.
What This Means for Your Program
Do not treat a lawsuit or a takedown as the end of an exposure. Operation Ghost Hook removed the seller’s central infrastructure, not the affiliate network using the kit. Continue monitoring for lookalike domains and phishing pages impersonating your brand well after any enforcement action makes headlines.
Keep DMARC enforcement focused on what it can actually stop. A strict p=reject policy on your own sending domains closes off forged From headers. It will never see a newly registered domain that never claimed to be yours in the first place, so it cannot be your only defense against brand impersonation.
Treat AiTM as a real-time MFA threat, not just a credential-theft threat. A kit that dynamically serves SMS, email, PIN, and app-based challenges is built specifically to defeat the assumption that multi-factor authentication makes a stolen password harmless.
Watch for phishing infrastructure that outlives its own operator’s arrest. A subscription model with thousands of independent affiliates means a single legal action, however large, only ever removes one node in a much larger network.
The Takeaway
Operation Ghost Hook did real damage: real servers seized, real money recovered, a real storefront shut down. What it could not do was reach into 700 affiliate accounts that never touched the seized infrastructure and stop them from registering new domains the same afternoon. That gap between the entity a lawsuit can name and the network that keeps operating without it is the same gap DMARC has always sat next to rather than inside. DMARC secures the name attackers try to steal. It was never built to see the name they invent instead.
DMARC confirms whether a message claiming your domain actually had the authority to send it. It cannot tell you when a phishing kit’s affiliate network has registered 700 new lookalike domains, or that one of those domains is running a real-time relay against whatever second factor your recipients use. Excello Mail turns your DMARC aggregate reports into a clear, continuous record of every domain and service sending as you, so your own authentication stays airtight while your team watches for the impersonation that happens on infrastructure DMARC was never built to see. Sign up for free to Excello Mail and get that foundation in place.