Smishing Kit Rebounds After Major Takedown

Infosecurity Magazine · High sophistication
Last updated September 3, 2026

Researchers say a “phishing-as-a-service” kit called Outsider kept generating new scam pages even after a major law-enforcement and industry takedown. The kit supports SMS-based lures that impersonate trusted brands and can capture payment details and MFA codes in real time using adversary-in-the-middle capabilities.

Key findings

  • Outsider (operated by “ChenLun”) continued operating after a coordinated takedown, with “more than 700 additional domains” observed after the disruption.
  • The kit provides “267 ready-made phishing templates” across multiple sectors and is “delivered through SMS” and managed via a “Telegram ecosystem.”
  • A documented smishing example impersonated Singapore’s LTA and used urgency plus tips to bypass phone spam filters, then collected vehicle and phone data and pushed victims to fraudulent payment pages.
  • The kit includes AiTM features and “live communication” (WebSockets) so operators can prompt for MFA challenges and capture entered data in real time, including partial form entries.
  • Captured data can include “bank credentials, PayPal information and authentication codes,” enabling account takeover and payment fraud.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance and accounts payable, Executives, IT/Helpdesk, Security team, Employees who manage fleet/transport or pay tolls/fees.
  • Affected industries: Government and transportation authorities, Financial services, Brokerage firms, Telecommunications providers, Postal services, Toll systems, Online payments.
  • Attack channels: smishing, website.
  • Impersonated: Singapore Land Transport Authority (LTA), A trusted brand portal (template-based phishing page).

Awareness takeaways

  • Treat SMS links as high-risk, especially messages claiming urgent issues, verify through the official app or official website instead of tapping message links.
  • Be suspicious if a message tells you how to bypass your phone’s spam protections, this is a strong sign of a scam.
  • Never enter MFA codes or authentication codes into pages reached from unexpected messages; attackers can capture them live to break into accounts.
  • Phishing infrastructure can quickly regenerate after takedowns, so organizations should continuously monitor for brand impersonation and new malicious pages/domains.

Red flags to watch for

  • Creates urgency around an “issue” and pushes immediate action via a link
  • Unusual guidance to bypass the phone’s spam filtering
  • Asks for sensitive identifiers (vehicle registration, phone number) and payment details via a linked portal
  • Unexpected MFA prompts on a page reached via a message link
  • Repeated requests to re-enter details or provide additional payment information
  • Authentication codes requested in the same flow as payment/identity data
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a text: “LTA alert: urgent data synchronization issue, tap this link now.” Looks official, right? Behind that text could be the Outsider smishing kit: 267 ready‑made fake sites, run over Telegram, that kept spinning up more than 700 new domains even after a big takedown. Tap the link, and a cloned LTA site asks for your vehicle number, phone, then jumps to a payment page and even live‑prompts for MFA codes using adversary‑in‑the‑middle tricks to grab everything you type. Here’s the move: if any SMS tells you to bypass your phone’s spam filter or fix an urgent issue, don’t tap the link, open the official app or website yourself and check from there.

Similar attacks

Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026
FBI: OAuth Consent Phishing Targets Prominent People

FBI: OAuth Consent Phishing Targets Prominent People

The FBI warns attackers are impersonating public figures on messaging apps and email to trick targets into approving a malicious OAuth app. Victims are sent links that lead to real Microsoft or Google login/consent screens, where approving access grants attackers ongoing access to emails and files.…

September 2, 2026
Quishing Emails Use QR Codes to Bypass Filters

Quishing Emails Use QR Codes to Bypass Filters

The article describes how attackers use QR codes in emails (“quishing”) to hide malicious links, push victims onto less-protected mobile phones, and steal credentials or MFA tokens. It also cites an FBI notice describing North Korea’s Kimsuky using QR codes in spearphishing emails targeting think…

August 18, 2026
Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake…

July 24, 2026