logo

Modular Phishing Kit Uses GitHub Pages to Steal Payment Card Details and Passwords

ID: 1e3bb79d-936c-581b-9f1d-a3bf27bc8707

STIX ID: report--1e3bb79d-936c-581b-9f1d-a3bf27bc8707

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Mayura Kathir

...
...

A sophisticated, long-running phishing campaign weaponizes GitHub Pages and third-party APIs (notably SheetBest/Google Sheets) to deploy institution-specific landing pages that harvest banking credentials and payment card data from Mexican customers; operators use obfuscated client-side scripts, randomized paths, Telegram forwarding, and automated GitHub workflows to increase resilience and evade takedown, and the report includes repository-hosted IOCs and recommended defensive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.