logo

Uncovering a Multi-Stage Phishing Kit Targeting Italy’s Infrastructure

ID: 997b3796-eb8a-52ad-9ed9-6d2ffc9a939f

STIX ID: report--997b3796-eb8a-52ad-9ed9-6d2ffc9a939f

Feed Name: Group-IB Blog

Threat Score
72/100

Date Published: 2025-11-13

Date Updated: 2026-04-28

...
...

**Executive Summary:** Group-IB discovered a sophisticated phishing-as-a-service kit impersonating Aruba.it that uses a four-stage flow (CAPTCHA anti-analysis, credential harvesting, fake payment form, and OTP/3D Secure interception) to steal account credentials and payment data; the kit uses pre-filled victim email links for realism and Telegram bots/chats for real-time exfiltration and distribution, illustrating an industrialized, supported phishing ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.