logo

A Multi-Stage Telegram Phishing Framework for Credential Theft and Detection Bypass

ID: 1c3c90b9-e0f2-55c9-a619-d045c5ed552a

STIX ID: report--1c3c90b9-e0f2-55c9-a619-d045c5ed552a

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-11-14

Date Updated: 2026-04-19

Author: Priya

...
...

**Executive summary:** Group-IB research details an industrialized, Telegram-centric phishing campaign impersonating Aruba S.p.A. that uses CAPTCHA gating, high-fidelity cloned login/payment pages, and staged forms to harvest credentials, full card details, and 3D Secure/OTP codes; stolen data is exfiltrated to Telegram bots, and the report lists network IOCs and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.