logo

Hackers Abuse SheetBest API to Exfiltrate Banking Credentials Into Google Sheets

ID: 27f72739-ce0a-5cec-aa40-0fc437cf4d4f

STIX ID: report--27f72739-ce0a-5cec-aa40-0fc437cf4d4f

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Varshini

...
...

Researchers uncovered a multi-year, financially motivated phishing campaign targeting at least 12 Mexican financial institutions that uses a fully serverless architecture hosted across many GitHub Pages repositories. The operation leverages modular phishing templates, obfuscated external JavaScript and the SheetBest API to exfiltrate credentials directly into attacker-controlled Google Sheets, uses social messaging-friendly Open Graph metadata to improve click-through rates, and employs distributed hosting and randomized paths for persistence and takedown resistance; multiple defanged domain indicators are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.