O phishing hospedado por Glitch usa CAPTCHAs falsos do Telegram & para atingir clientes de cooperativas de crédito federais da Marinha

June 2, 2025

Summary

Key findings

Glitch abused to create and deploy phishing websites

Navy Federal Credit Union

Phishing pages behind a fake CAPTCHA

Telegram abused to exfiltrate credentials and bypass MFA

Conclusion

Disclosure

Data Analysis

IOCs

author image

Jan Michael Alcantara

Jan Michael Alcantara is an experienced incident responder with a background on forensics, threat hunting, and incident analysis.
Jan Michael Alcantara is an experienced incident responder with a background on forensics, threat hunting, and incident analysis.
Keep a close eye on The Lens