Glitch-hosted Phishing Uses Telegram & Fake CAPTCHAs to Target Navy Federal Credit Union Customers

June 2, 2025

Summary

Key findings

Glitch abused to create and deploy phishing websites

Navy Federal Credit Union

Phishing pages behind a fake CAPTCHA

Telegram abused to exfiltrate credentials and bypass MFA

Conclusion

Disclosure

Data Analysis

IOCs

author image

Jan Michael Alcantara

Jan Michael Alcantara is an experienced incident responder with a background on forensics, threat hunting, and incident analysis.
Jan Michael Alcantara is an experienced incident responder with a background on forensics, threat hunting, and incident analysis.
Keep a close eye on The Lens