Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25)
Massive Smishing Campaign Abuses Gemini AI to Target Mobile (TL-2026-1479), also tracked as Outsider, is a high-severity phishing campaign, first published 2026-07-18. It is attributed to Outsider Enterprise (China) with medium confidence, affects Google Gemini AI (consumer and API access), maps to 15 MITRE ATT&CK techniques (T1056.003, T1071.001, T1119), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1479
- Threat ID
- TL-2026-1479
- Also known as
- Outsider, Outsider PhaaS, Outsider Enterprise smishing network
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-18
- Last reviewed
- 2026-07-18
- Attribution
- Outsider Enterprise
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- consumer mobile-subscribers, financial-services, government administration, transportation-tolling, logistics-delivery, technology
- Target regions
- united states of america, North America
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Massive Smishing Campaign Abuses Gemini AI to Target Mobile
Malware and tooling: Gemini AI, Outsider (PhaaS platform)
A China-based phishing-as-a-service network dubbed "Outsider Enterprise" ran a smishing campaign impersonating toll agencies (E-ZPass), USPS package delivery, state DMVs, banks, and Google itself, sending 2.5 million fraudulent SMS in a single two-week window and standing up 9,000+ fake sites and 1.59M+ malicious URLs to harvest credentials and payment-card data from over 100,000 victims. Google sued the network in Manhattan federal court on 2026-06-12, alleging operators jailbroke Gemini AI by framing malicious requests as harmless "gift redemption page" coding assistance to mass-produce phishing-page HTML.
How Massive Smishing Campaign Abuses Gemini AI to Target Mobile works
Zimperium's Mobile Threat Watch (2026-07-06) flagged a large-scale smishing operation tied to a Chinese cybercrime network that Google, in a June 2026 federal civil lawsuit (Google LLC v. Does 1-25, S.D.N.Y./Manhattan, Court Listener docket 73476270), identifies as "Outsider Enterprise." The network operates a self-service phishing-as-a-service (PhaaS) platform sold via a Telegram bot (@OutsiderCodeBot, later disabled) for $88/week or $200/month, giving low-skill affiliates access to 290+ prebuilt brand-impersonation templates (Google, YouTube, USPS, financial institutions, state DMV agencies, and toll operators including New York's E-ZPass) plus real-time keystroke-logging and campaign-performance dashboards on the resulting phishing pages.
The operation is internally divided into specialized crews coordinated over Telegram: a Developer Group that builds phishing software/templates, a Data Broker Group that curates target phone-number/identity lists, a Spammer Group that runs bulk SMS delivery tooling, and a Theft Group that monetizes stolen credentials/payment data and launders proceeds (part of an estimated $1.9B in FBI-tracked PhaaS losses tied to an estimated 3.87M stolen credit cards since July 2023).
Google's suit is the company's first alleging abuse of its own Gemini AI tooling: Outsider operators prompted Gemini (and other AI platforms) with requests framed as benign programming assistance -- e.g., asking for HTML to build a "gift redemption page" with specific functional requirements while avoiding JavaScript dependencies that could trip safety filters -- then imported the AI-generated code directly into the Outsider platform to stand up live, functioning credential-theft pages at scale. Google states it has since disabled the Gemini accounts and infrastructure identified as linked to this abuse, and notes that Android's built-in defenses intercept over 10 billion malicious/suspicious messages per month platform-wide, providing scale context for the volume Outsider represents.
Scale: between 2025-11-14 and 2026-04-14, Google tracked over 9,000 distinct fraudulent websites and 1.59 million malicious URLs tied to the Outsider phishing service. In the two-week window of 2026-05-18 through 2026-06-01 alone, the network sent an estimated 2.5 million spam texts to Android users, generating 55,000 user-flagged spam complaints (over two per minute). Total victims are estimated at 100,000+, with losses in the millions of dollars.
Google's lawsuit follows, by roughly seven months, its November 2025 action against a separate China-based PhaaS operation, "Lighthouse," which ensnared over 1 million victims across 120 countries -- indicating a broader, organized Chinese smishing-as-a-service ecosystem (of which the previously reported "Smishing Triad" is a related, adjacent brand). Google states it is pursuing the Outsider Enterprise lawsuit to obtain injunctive relief to dismantle the network's infrastructure and is coordinating with AT&T, T-Mobile, and Verizon to block Outsider-linked SMS traffic at the carrier level. FBI Cyber Division assistant director Brett Leatherman publicly acknowledged the case as an example of criminal AI misuse in fraud operations; a parallel law-enforcement effort styled "Operation Ghost Hook" (part of the broader "Operation Riptide") has seized Outsider-linked domains from U.S. registrars/hosts (redirecting them to FBI splash pages) and confiscated roughly $100,000 in USDT from Outsider payment wallets.
No software vulnerability or CVE is implicated -- this is a social-engineering/PhaaS campaign, not an exploit chain, so no patch or affected-version data applies.
MITRE ATT&CK techniques used in TL-2026-1479
Credential Access
Command and Control
Collection
Execution
Initial Access
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1585.001 Social Media Accounts; T1587.001 Malware; T1588.007 Artificial Intelligence; T1608.005 Link Target
Reconnaissance
T1589 Gather Victim Identity Information
Impact
initial-access
stealth
Affected products and versions in Massive Smishing Campaign Abuses Gemini AI to Target Mobile
- Google — Gemini AI (consumer and API access)
Vulnerable versions: N/A -- abused via social-engineered prompt framing, not a software defect
Fixed in: N/A -- Google pursuing civil/injunctive and infrastructure-takedown remedies, not a patch; Google has disabled Gemini accounts/infrastructure linked to the abuse - N/A (ecosystem-wide) — Android SMS/RCS messaging ecosystem (carrier-agnostic)
Vulnerable versions: Android mobile subscribers on AT&T, T-Mobile, Verizon, and other U.S. carriers
Fixed in: N/A -- mitigated via carrier-level SMS filtering and domain/account takedowns, not a version fix
Remediation for Massive Smishing Campaign Abuses Gemini AI to Target Mobile
Immediate actions
- Do not click links in unsolicited SMS claiming to be from toll operators, delivery carriers, banks, or government agencies -- navigate directly to the official app/site instead
- Report suspected smishing texts to carriers (forward to 7726/'SPAM') and to the FTC (reportfraud.ftc.gov)
- Enable carrier-level spam/smishing filtering (AT&T, T-Mobile, Verizon are actively blocking Outsider-linked traffic per Google's coordination)
- If credentials or payment data were entered on a suspicious link, rotate the affected password/PIN immediately and contact the card issuer to flag/reissue
Workarounds
- Treat any SMS containing a shortened or unfamiliar link plus urgency language (unpaid toll, failed delivery, account suspension) as untrusted regardless of apparent sender ID, since sender-ID spoofing is trivial in SMS
Longer-term hardening
- Deploy mobile threat defense (MTD) with URL/SMS phishing detection on managed devices
- User-awareness training specifically on toll-fee and delivery-notice smishing lures, which convert at high rates due to plausible timing/context
- Enterprises should monitor for employee-reported smishing impersonating internal IT/HR alongside consumer-facing lures, since PhaaS kits are template-driven and rapidly repurposed
- Track legal/law-enforcement takedown actions (Google civil suits, FBI Operation Ghost Hook/Riptide) for IOC and domain-seizure updates feeding blocklists
- AI platform operators should harden prompt-based safety filters against 'benign pretext' framing (e.g., 'gift redemption page' coding requests) that decompose malicious intent into individually innocuous-looking prompts
Timeline of Massive Smishing Campaign Abuses Gemini AI to Target Mobile
- Start of the Google-tracked window in which 9,000+ Outsider-linked fraudulent websites and 1.59M+ malicious URLs were generated.
- Google files a separate lawsuit against the China-based 'Lighthouse' PhaaS operation, which had ensnared over 1 million victims across 120 countries -- roughly seven months before the Outsider Enterprise suit.
- End of the tracked window for the 9,000+ fraudulent sites / 1.59M+ URL count tied to Outsider Enterprise.
- Start of a two-week high-volume period in which Outsider Enterprise sent an estimated 2.5 million spam texts to Android users.
- End of the two-week SMS blast window; 55,000 Android user spam-flag complaints recorded (over two per minute).
- Google states it is coordinating with AT&T, T-Mobile, and Verizon to block SMS traffic originating from the Outsider Enterprise network; Google notes Android's built-in defenses intercept over 10 billion malicious/suspicious messages per month platform-wide as scale context.
- FBI Cyber Division (assistant director Brett Leatherman) publicly acknowledges the case; disclosure of Operation Ghost Hook (part of Operation Riptide), including domain seizures with FBI splash-page redirects and seizure of roughly $100,000 in USDT from Outsider payment wallets.
- Google discloses it has disabled the Gemini accounts and associated infrastructure identified as linked to the Outsider Enterprise abuse.
- Google LLC files civil suit (Google LLC v. Does 1-25, Manhattan federal court / Court Listener docket 73476270) against the Outsider Enterprise network, alleging Gemini AI abuse to mass-generate phishing-page code; first Google lawsuit alleging Gemini misuse.
- Zimperium's Mobile Threat Watch publishes analysis of the smishing campaign's toll/delivery/government lures and Gemini AI abuse, the source article for this threat record.
Sources cited for Massive Smishing Campaign Abuses Gemini AI to Target Mobile
- Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
- Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks
- Google sues China-based scammers using Gemini AI for fraud
- Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
- Google sues Chinese smishing ring using Gemini AI for phishing pages
- Google Sues Scam Ring That Used Gemini AI to Flood Phones With Fake Texts
- Google sues Chinese scammers using Gemini AI for fraud
- Google sues scam ring that used Gemini AI to build fraud sites
- Google LLC v. Does 1-25 (Docket 73476270)
Threats related to Massive Smishing Campaign Abuses Gemini AI to Target Mobile
- FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini) Phishing-as-a-Service and Smishing Network (Operation Riptide / Operation Ghost Hook)
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
- 2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu, Lighthouse, Lucid, Smishing Triad)
- TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms
Detection coverage for TL-2026-1479
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1479 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.