Advanced Phishing Campaign Targets Customers of Major Italian Web Host Aruba S.p.A.

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer

Key Takeaways

A significant Aruba phishing campaign has been identified, targeting customers of the major Italian web hosting and IT services provider to steal sensitive user credentials and credit card details. 

Given that Aruba serves over 5.4 million customers, a single compromised account could expose critical business assets, including hosted websites, domain controls, and corporate email environments. 

Phishing Kit with Telegram Bots Deployed

According to a recent Group-IB report, the campaign utilizes a sophisticated phishing kit with Telegram bots, which is being sold as a service to other cybercriminals. Victims are lured via emails about expiring services or failed payments to a fraudulent login page.

The phishing page mimics the official Aruba.it webmail login portal
The phishing page mimics the official Aruba.it webmail login portal | Source: Group-IB

The phishing operation's reliance on Telegram for coordination and data exfiltration marks a notable level of operational sophistication. 

Recommendations for Businesses and End Users

Among the recommendations for organizations and service providers are:

End users should remain skeptical of any email that uses any social engineering techniques, like creating urgency or fear. 

Recent reports show that phishing and scam threats are surging in relation to the shopping season and holidays – mobile phishing campaigns are increasing, and over 1,000 websites impersonating luxury brands have been registered. 


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: