Serverless Phishing Kit on GitHub Targets Mexican Banks
ID: 5e83fd3d-905b-53fc-b4f2-182d49617c2e
STIX ID: report--5e83fd3d-905b-53fc-b4f2-182d49617c2e
Feed Name: Infosecurity Magazine (News)
Threat Score
Group-IB analyzed the "GitBait" phishing operation that stole banking credentials from customers of at least 12 Mexican banks over ~3 years by hosting cloned bank pages on GitHub Pages and sending captured logins to Google Sheets via SheetBest; the modular kit, automated deployments, obfuscated payload hosting, and domain rotation let operators maintain and rapidly redeploy pages while evading traditional blocklists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
