Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Serverless Phishing Kit on GitHub Targets Mexican Banks

June 17, 2026

Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards

June 17, 2026

Sensitive Enterprise Data Uploads to AI Models Double in a Year

June 17, 2026
Facebook X (Twitter) Instagram
Wednesday, June 17
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Serverless Phishing Kit on GitHub Targets Mexican Banks
News

Serverless Phishing Kit on GitHub Targets Mexican Banks

Team-CWDBy Team-CWDJune 17, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A long-running phishing operation has been stealing banking credentials from customers of Mexican financial institutions without running any server infrastructure of its own, instead hiding inside trusted cloud platforms.

New analysis from Group-IB detailed the campaign, which it called GitBait, and tied it to attacks on at least 12 financial institutions in Mexico over roughly three years.

Instead of a dedicated backend, GitBait hosted its fake bank pages on GitHub Pages and funneled stolen logins through SheetBest, a legitimate service that writes data straight into Google Sheets, leaving little infrastructure to seize.

Group-IB counted more than 100 GitHub-hosted domains tied to the campaign, each serving several phishing pages, and said it has reported all of them to GitHub.

Read more on large-scale phishing kits: Quantum Route Redirect Phishing Kit Democratizes Cyber-Attacks

Inside a Serverless Operation

At the center was a modular phishing kit with a desktop-and-mobile operator panel that let attackers pick a target bank and generate a matching fake page.

Each GitHub repository held duplicated pages, so any page that was removed could be redeployed quickly.

Victims landed on a page cloning a bank’s branding, then a form that captured usernames, customer IDs, passwords and card details. A script grabbed the entry, shipped it to SheetBest, then showed a fake verification screen to maintain user trust.

Group-IB could not confirm how victims were lured, but the evidence pointed to direct messages. The phishing pages carried crafted Open Graph tags that rendered a convincing bank-branded preview card when a link was shared on WhatsApp, Telegram or SMS, while a noindex tag kept them out of search results.

Commit records on one repository revealed an operation under active upkeep:

  • 66 commits, indicating continuous development

  • Three contributor accounts, some sharing an email address

  • Automated publishing via Jekyll and GitHub Actions

  • An endpoint rotation by an operator account still active at the time of analysis

The pages also pulled obfuscated JavaScript from randomized paths, letting operators swap payloads without altering the page and frustrating static analysis.

Beyond Blocklists

Group-IB framed GitBait as part of a broader shift in which criminals lean on everyday cloud services and ready-made kits rather than custom malware and self-hosted servers, echoing the rise of phishing-as-a-service platforms seen in the last few years.

Because the operation relied on trusted domains, the firm warned that blocklists of known-bad sites offer little protection.

Instead, Group-IB urged banks to watch GitHub for brand abuse and flag unexpected traffic to services like SheetBest, leaning on behavioral detection, multi-factor authentication (MFA) and transaction alerts.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAnthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards
Team-CWD
  • Website

Related Posts

News

Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards

June 17, 2026
News

EU Security Experts to Support Ukrainian Orgs in Case of Cyber-Attacks

June 17, 2026
News

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

June 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why that next data breach alert could be a trap

April 18, 2026

Is Poshmark safe? How to buy and sell without getting scammed

February 19, 2026

Chronology of a Skype attack

February 5, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.