Hackers Abuse SheetBest API to Exfiltrate Banking Credentials Into Google Sheets
ID: 27f72739-ce0a-5cec-aa40-0fc437cf4d4f
STIX ID: report--27f72739-ce0a-5cec-aa40-0fc437cf4d4f
Feed Name: Cyber Press
Researchers uncovered a multi-year, financially motivated phishing campaign targeting at least 12 Mexican financial institutions that uses a fully serverless architecture hosted across many GitHub Pages repositories. The operation leverages modular phishing templates, obfuscated external JavaScript and the SheetBest API to exfiltrate credentials directly into attacker-controlled Google Sheets, uses social messaging-friendly Open Graph metadata to improve click-through rates, and employs distributed hosting and randomized paths for persistence and takedown resistance; multiple defanged domain indicators are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
