GitBait Phishing Campaign Targets 12 Mexican Banks via GitHub Pages
ID: a03e5df2-a02e-5b30-a554-bc3292720881
STIX ID: report--a03e5df2-a02e-5b30-a554-bc3292720881
Feed Name: securityonline.info
Group-IB uncovered the long-running 'GitBait' phishing campaign that abuses free GitHub Pages and the SheetBest API to host cloned login pages for at least 12 Mexican banks, harvesting usernames, passwords, customer IDs and card data in real time; the operation used 100+ domains over ~3 years, employed link-preview metadata and robots noindex to evade detection, and leveraged a reusable serverless kit—recommended defenses include brand-impersonation monitoring, hunting for unexpected POSTs to SheetBest, behavioral detection, MFA, and reporting suspicious links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
