A Multi-Stage Telegram Phishing Framework for Credential Theft and Detection Bypass
ID: 1c3c90b9-e0f2-55c9-a619-d045c5ed552a
STIX ID: report--1c3c90b9-e0f2-55c9-a619-d045c5ed552a
Feed Name: Cyber Press
Threat Score
**Executive summary:** Group-IB research details an industrialized, Telegram-centric phishing campaign impersonating Aruba S.p.A. that uses CAPTCHA gating, high-fidelity cloned login/payment pages, and staged forms to harvest credentials, full card details, and 3D Secure/OTP codes; stolen data is exfiltrated to Telegram bots, and the report lists network IOCs and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
