www.group-ib.com
GitBait Phishing Campaign Targets Mexican Banks via GitHub Pages
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A modular phishing operation named GitBait has been uncovered, targeting at least 12 Mexican financial institutions over three years. This campaign utilizes GitHub Pages to host fake banking websites, employing a serverless architecture that leverages the SheetBest API for credential exfiltration. The phishing kit allows attackers to generate institution-specific pages, capturing sensitive information such as usernames, passwords, and payment card details. Group-IB reported over 100 GitHub-hosted domains associated with this operation, which has shown long-term persistence and continuous development. Victims are likely lured through direct messages on platforms like WhatsApp and Telegram, with the phishing pages designed to mimic legitimate bank branding. The campaign highlights a trend where cybercriminals exploit trusted cloud services instead of traditional server infrastructures.
Key Points: • GitBait targets at least 12 Mexican banks using GitHub Pages for phishing. • The operation employs a modular phishing kit for generating fake bank pages. • Over 100 GitHub-hosted domains are linked to this long-running campaign.