GitBait Phishing Campaign Abuses GitHub Pages to Target Financial Firms
Key Takeaways A sophisticated phishing campaign, “GitBait,” has been targeting financial institutions in Mexico for over three years. The attackers exploit GitHub Pages for hosting highly...
Key Takeaways
- A sophisticated phishing campaign, “GitBait,” has been targeting financial institutions in Mexico for over three years.
- The attackers exploit GitHub Pages for hosting highly convincing fake banking portals, leveraging the platform’s trusted reputation and HTTPS.
- The campaign utilizes a serverless architecture, exfiltrating stolen credentials in real-time to Google Sheets via the SheetBest API or to Telegram bots.
- At least 24 Mexican financial entities, including local and international banks, have been targeted.
- The modular design of the phishing kit allows threat actors to easily adapt and target new institutions, making takedowns challenging.
GitBait: Sophisticated Phishing Targets Mexican Financial Sector via GitHub Pages
A highly organized phishing operation, dubbed “GitBait,” is actively compromising the financial sector in Mexico, demonstrating an advanced level of precision rarely seen in credential theft campaigns. This persistent threat has been quietly evolving for over three years, utilizing a stealthy approach to deceive victims.
Table Of Content
The GitBait campaign leverages GitHub Pages, a widely recognized and trusted free hosting service, to deploy meticulously crafted fake banking portals. These malicious sites are nearly indistinguishable from legitimate financial institution websites, tricking users into divulging sensitive information such as login credentials and payment card details without suspicion. Details of the campaign were released in a recent report.
Analysis of historical infrastructure indicates the GitBait campaign has maintained continuous activity for more than three years, consistently refining its tactics and expanding its list of targets. The operation has successfully aimed at a minimum of 24 financial institutions operating within Mexico, encompassing both indigenous banks and foreign entities with a local presence.
Security researchers at Group-IB discovered the campaign, noting its fully serverless architecture. This innovative setup routes stolen credentials through SheetBest, a third-party API service, directly into Google Sheets controlled by the attackers in real-time. Group-IB’s report, shared with Cyber Security News (CSN), highlights the modular nature of the GitBait infrastructure, which enables threat actors to quickly swap phishing templates and target new institutions without requiring a complete rebuild of their operational setup.
More than 200 domains have been linked to this extensive campaign. Each domain hosts multiple phishing pages under directory paths such as “cancelacion,” “soporte,” and “mbw,” designed to mimic legitimate banking service categories. These specific directory structures also aid the operation in evading automated detection systems that rely on established lists of malicious domains. Furthermore, the phishing pages are optimized for seamless display on both desktop and mobile devices, indicating a deliberate strategy to maximize victim engagement across all platforms. The credential harvesting scheme operates without the need for a traditional command-and-control server.
In at least one documented instance, an alternative exfiltration method was observed, where victim data was sent in real-time to a Telegram bot. This was achieved through hardcoded tokens and chat IDs embedded within the page’s JavaScript. The ongoing maintenance and evolution of the campaign are evident through commit histories across multiple GitHub repositories, suggesting a collaborative and actively managed group of operators behind GitBait.
Exploiting GitHub Pages for Trust and Evasion
The core of the GitBait operation’s success lies in its exploitation of GitHub Pages. This platform’s inherent trustworthiness and default HTTPS coverage mean that many automated security tools do not flag hosted content as suspicious. Threat actors capitalize on this trust to deploy phishing pages that bypass standard blocklist checks, reaching their intended targets more effectively.
Each GitHub repository associated with the campaign contains duplicated phishing content under various directory paths. This redundancy makes takedowns challenging, as removing one specific path does not eliminate other active phishing instances. The phishing kit incorporates an internal campaign selector, allowing operators to choose which bank to impersonate and then generate a corresponding fraudulent URL.
The impersonation landing pages meticulously replicate the visual identity, layout, and navigation of legitimate banking portals. This high fidelity creates a false sense of security before victims are directed to credential-harvesting forms. These forms collect critical information, including usernames, passwords, customer IDs, and payment card details, through a multi-stage process designed to mimic a genuine online banking session.
Centralized Credential Theft Through SheetBest API
Upon a victim’s submission of their information, client-side JavaScript code intercepts the form data before it is processed by the browser. The stolen data is then serialized into JSON format and dispatched via a POST request to the SheetBest API, which directly populates an attacker-controlled Google Sheet. This serverless model significantly reduces the need for costly backend infrastructure, thereby lowering operational expenses and making attribution considerably more difficult for defenders.
Group-IB has proactively reported all identified phishing pages and domains to GitHub. Financial institutions are strongly advised to implement proactive monitoring for GitHub Pages repositories that attempt to impersonate their brand. Specific naming patterns to watch for include “brand-soporte” or “brand-cancelacion.”
What You Should Do
- Proactive Monitoring: Financial institutions should actively monitor GitHub Pages for repositories impersonating their brand using patterns like “brand-soporte” or “brand-cancelacion.”
- Network Traffic Analysis: Track unexpected outbound POST requests to
api.sheetbest[.]comfrom user-facing web sessions to detect credential exfiltration. - Enhanced Customer Protection: Implement behavioral detection mechanisms and real-time transaction alerts to protect customers even if their credentials are compromised.
- Employee Training: Conduct regular security awareness training for employees to recognize sophisticated phishing attempts, especially those leveraging trusted domains.
- Threat Intelligence Sharing: Share threat intelligence with peer institutions and regulatory bodies to facilitate a coordinated and rapid response across the financial sector.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | soporte-index.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-index69.github[.]io | GitHub Pages phishing domain |
| Domain | sntdr-soporte.github[.]io | GitHub Pages phishing domain |
| Domain | v9-soporte.github[.]io | GitHub Pages phishing domain |
| Domain | soporte169.github[.]io | GitHub Pages phishing domain |
| Domain | soporte1505.github[.]io | GitHub Pages phishing domain |
| Domain | soporte16032k.github[.]io | GitHub Pages phishing domain |
| Domain | soporte96.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-bmw.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-r2.github[.]io | GitHub Pages phishing domain |
| Domain | api.sheetbest[.]com | SheetBest API used for credential exfiltration |
| Domain | soporte5014.github[.]io | GitHub Pages phishing domain |
| Domain | soporte15052014.github[.]io | GitHub Pages phishing domain |
| Domain | soporte20032k.github[.]io | GitHub Pages phishing domain |
| Domain | soporte250.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-index69.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-bnw.github[.]io | GitHub Pages phishing domain |
| Domain | fldsmdrc-95.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-bx.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-index.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-cw.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-bk.github[.]io | GitHub Pages phishing domain |
| Domain | sntdrsoporte-jatencionf.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-jatencionf.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-j-atencion.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-bh.github[.]io | GitHub Pages phishing domain |
| Domain | respaldo95.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-indexg1.github[.]io | GitHub Pages phishing domain |
| Domain | gnilsoporte.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-gn-il.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-gnil.github[.]io | GitHub Pages phishing domain |
| Domain | goil-soporte.github[.]io | GitHub Pages phishing domain |
| Domain | gnil-soporte.github[.]io | GitHub Pages phishing domain |
| Domain | soporte-sh.github[.]io | GitHub Pages phishing domain |
| Domain | soportecgj.github[.]io | GitHub Pages phishing domain |
| Domain | support-gh.github[.]io | GitHub Pages phishing domain |
| IP Address | 176.97.214[.]92 | Remote address for SheetBest API credential submission |
| Operator Account | ss-soporte (GitHub) | rronromoBgmail[.]com — Initial repository setup and base infrastructure creation |
| Operator Account | ce-soporte (GitHub) | jejcgsbsbs Bgmail[.]com — Activation of GitHub Pages hosting |
| Operator Account | soporte-swjejcgsbsbsBgmail[.]com (GitHub) | Addition of new institution templates and removal of others |
| Operator Account | soporte-BRAND-NAMEB-soperte (GitHub) | hig3naarool101Bgmail[.]com — Updates to credential harvesting pages |
| File Hash (CSS) | sha256 bootstrap v5.3.0-alpha1 CSS SHA256 hash (see report) | Bootstrap CSS SRI hash used across phishing pages |
| File Hash (JS) | sha256 bootstrap v5.3.0-alpha1 JS SHA256 hash (<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/34c54cfb-6468-4308-a894-abac1fa7acb9/GitBait-Phishing-Campaign-Abuses-GitHub-Pages-to-Attack-Financial-Institutions.pdf?AWSAccessKeyId=ASIA2F3EMEYEVVFW6FD6&Signature=hLGXItcflhwKrL3Dbav5n1MB%2Fbs%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIFPGrdAApUOVnZYyriVzvyxynWn63REqtFxxUojUqcHbAiBRX8ipM0ANNPmr3G75n76C5EIjOQqF5ZeopSGaYKyLcyr8BAiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMvnMFg%2BACP1k7lBeCKtAEljoH%2BZvuvP%2Fwk0iiiJEHoVI71JWuNRVbi12n%2BXIw1KUWbKMPspwNn3Jd6ttqYlPdAaXdkr2oBbR4CbiQcEDLiFIybgS4UM0srdsQQrIO9DpxqbgFaj2sgsDQWFQ47hMf6ocOI0uXJbCqW1gAYpT7XJ7fYS8VJcbrnplBXaYGKkPNuVnqE5UdXJCyOBUYRologwR77V0ESd3TR35rTShCPc68fKBLF46cOvDdlWlf0QUvX1h%2F%2Bb9%2F04tk4ck69AmAhJc5OKI%2BDMq2s
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.