Uncovering a Multi-Stage Phishing Kit Targeting Italy’s Infrastructure
ID: 997b3796-eb8a-52ad-9ed9-6d2ffc9a939f
STIX ID: report--997b3796-eb8a-52ad-9ed9-6d2ffc9a939f
Feed Name: Group-IB Blog
Threat Score
**Executive Summary:** Group-IB discovered a sophisticated phishing-as-a-service kit impersonating Aruba.it that uses a four-stage flow (CAPTCHA anti-analysis, credential harvesting, fake payment form, and OTP/3D Secure interception) to steal account credentials and payment data; the kit uses pre-filled victim email links for realism and Telegram bots/chats for real-time exfiltration and distribution, illustrating an industrialized, supported phishing ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
