Skip to content
GitBait Phishing Campaign Targets Mexican Banks via GitHub Pages

GitBait Phishing Campaign Targets Mexican Banks via GitHub Pages

First seen 17 Jun 2026, 14:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 18, 2026 at 14:11 UTC
  • •GitBait targets at least 12 Mexican banks using GitHub Pages for phishing.
  • •The operation employs a modular phishing kit for generating fake bank pages.
  • •Over 100 GitHub-hosted domains are linked to this long-running campaign.

A modular phishing operation named GitBait has been uncovered, targeting at least 12 Mexican financial institutions over three years. This campaign utilizes GitHub Pages to host fake banking websites, employing a serverless architecture that leverages the SheetBest API for credential exfiltration. The phishing kit allows attackers to generate institution-specific pages, capturing sensitive information such as usernames, passwords, and payment card details. Group-IB reported over 100 GitHub-hosted domains associated with this operation, which has shown long-term persistence and continuous development. Victims are likely lured through direct messages on platforms like WhatsApp and Telegram, with the phishing pages designed to mimic legitimate bank branding. The campaign highlights a trend where cybercriminals exploit trusted cloud services instead of traditional server infrastructures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 114d ago How this analysis works

Timeline

2026-06-17
GitBait phishing campaign detailed
Group-IB published an analysis revealing a phishing operation targeting 12 Mexican banks using GitHub Pages for hosting and SheetBest for credential exfiltration.
Group-IB
2026-06-17
Phishing kit functionality explained
The GitBait phishing kit allows attackers to generate institution-specific landing pages, capturing sensitive customer information.
Infosecurity-Magazine
2026-06-17
Continuous development observed
Commit records revealed active maintenance of the phishing kit, indicating ongoing development and operational upkeep.
Infosecurity-Magazine

More articles in this cluster (4)