Web services giant Aruba spoofed in major phishing scam – here’s what to look out for to stay safe
- Cybercriminals spoofed Aruba using a stealthy, automated phishing framework with CAPTCHA and Telegram bots
- Phishing pages mimicked Aruba’s webmail portal, stealing credentials via fake service alerts
- Aruba’s large user base made it a high-value target for industrial-scale credential theft
Security researchers Group-IB have published details of a new scam targeting Aruba users which turned out to be a part of a “sophisticated phishing framework”.
The team found cybercriminals had created a “fully automated, multi-stage platform” providing both efficiency and stealth, employing CAPTCHA filtering to evade security scans, pre-fills victim data to increase credibility, and uses Telegram bots to exfiltrate stolen credentials and payment information.
The goal of the phishing kit is to achieve “industrial-scale credential theft”, Group-IB said, adding that it “drastically lowers” the technical barrier to entry, and enables less skilled actors to launch convincing campaigns at scale, and virtually overnight.
Targeting Aruba
The modus operandi here is rather usual – the attack starts with a carefully crafted email, warning users about an expiring service or a failed payment. These themes were chosen because Aruba itself often warns its customers about them, albeit without the dramatic sense of urgency the phishing emails come with.
The messages come with a link to “one of many” phishing pages that “meticulously mimic” the official Aruba.it webmail login portal, Group-IB added. Victims that do not spot the ruse and try to log in end up relaying their credentials to the attackers via Telegram, who can later either use it, or sell it on the dark web.
Aruba was chosen because it is “deeply embedded in Italy’s digital infrastructure,” Group-IB stressed, adding that it is currently serving more than 5.4 million customers.
“Such a target offers significant payoff: compromising a single account can expose critical business assets, from hosted websites to domain controls and email environments,” the researchers concluded.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Defending against phishing attacks remains simple – think before you click, keep your software updated, and run a strong endpoint protection solution.

The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
Cybercriminals spoofed Aruba using a stealthy, automated phishing framework with CAPTCHA and Telegram bots Phishing pages mimicked Aruba’s webmail portal, stealing credentials via fake service alerts Aruba’s large user base made it a high-value target for industrial-scale credential theft Security researchers Group-IB have published details of a new scam targeting…
Recent Posts
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- NordVPN Coupons and Deals: 77% Off in June 2026
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023