Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation campaigns through texts sent over AT&T, T-Mobile, and Verizon. Google linked the network to 9,000 fake websites and more than a million fraudulent URLs, and authorities say the activity has driven theft of more than 3.8 million credit card records and about $1.9 billion in losses. The latest response includes an FBI-led takedown with Google and Black Lotus Labs, seizures of infrastructure and funds, and carrier blocking efforts to stop fraudulent messages before they reach users.
Related Happenings
Google hit by network compromise
Incident
H score42
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Google hit by network compromise
IncidentAbout this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
FBI seizure of NetNut proxy domains
Law Enforcement
H score33
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
About this happening:
The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizure of NetNut proxy domains
Law EnforcementAbout this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizes NetNut and Popa botnet domains
Law Enforcement
H score34
First: 02.07.2026 22:27
Last: 02.07.2026 22:27
Sources 1
About this happening:
The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
FBI seizes NetNut and Popa botnet domains
Law EnforcementAbout this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
Pre-World Cup 2026 fraud surge across partner spoofing, fake sportsbook apps, and travel domains
Trend
H score31
First: 30.06.2026 14:30
Last: 30.06.2026 14:30
Sources 1
About this happening:
Pre-tournament fraud around FIFA World Cup 2026 intensified across partners, sportsbook users, and travel buyers, raising the risk of impersonation, payment diversion,...
Pre-World Cup 2026 fraud surge across partner spoofing, fake sportsbook apps, and travel domains
TrendAbout this happening: Pre-tournament fraud around FIFA World Cup 2026 intensified across partners, sportsbook users, and travel buyers, raising the risk of impersonation, payment diversion,...
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityAbout this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
Timeline
-
12.06.2026 21:59 1 articles · 1mo ago
Outsider infrastructure is identified across 9,000 fake websites
Campaign Scope UpdateGoogle says 9,000 fake websites and more than 1.59 million fraudulent URLs tied to Outsider were identified between November 14, 2025, and April 14, 2026, showing the scale of the phishing service's brand-impersonation infrastructure.
Show sources
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing — thehackernews.com — 12.06.2026 21:59
-
12.06.2026 21:59 1 articles · 1mo ago
Outsider floods Android users with 2.5 million smishing messages
Victim Impact UpdateIn a two-week period from May 18 to June 1, 2026, Outsider was responsible for 55,000 spam texts flagged by Android users and 2.5 million messages containing links to Outsider-generated websites, indicating large-scale mobile delivery of phishing lures.
Show sources
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing — thehackernews.com — 12.06.2026 21:59
-
12.06.2026 21:59 2 articles · 1mo ago
Google files lawsuit to dismantle the Outsider smishing network
Legal Policy Action UpdateOn June 12, 2026, Google said it is pursuing legal action against a Chinese cybercrime network accused of using Gemini to generate phishing pages and run SMS smishing campaigns through Outsider, and it is partnering with AT&T, T-Mobile, and Verizon to block the messages from reaching customers.
Show sources
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing — thehackernews.com — 12.06.2026 21:59
- FBI disrupts massive AI-powered phishing service using a million URLs — www.bleepingcomputer.com — 14.06.2026 17:36