Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ShieldBreak Vulnerability in Windows Defender Allows Remote Code Execution
August 12, 2026
CAV3RN malware uses Google Apps Script to hide C2 traffic
August 12, 2026
Sandworm Uses Fake Job Interviews to Distribute Trojanized WireGuard VPN
August 12, 2026
Home/Threats/GitBait Phishing Campaign Abuses GitHub Pages to Target Financial Firms
Threats

GitBait Phishing Campaign Abuses GitHub Pages to Target Financial Firms

Key Takeaways A sophisticated phishing campaign, “GitBait,” has been targeting financial institutions in Mexico for over three years. The attackers exploit GitHub Pages for hosting highly...

Marcus Rodriguez
Marcus Rodriguez
June 17, 2026 5 Min Read
53 0

Key Takeaways

  • A sophisticated phishing campaign, “GitBait,” has been targeting financial institutions in Mexico for over three years.
  • The attackers exploit GitHub Pages for hosting highly convincing fake banking portals, leveraging the platform’s trusted reputation and HTTPS.
  • The campaign utilizes a serverless architecture, exfiltrating stolen credentials in real-time to Google Sheets via the SheetBest API or to Telegram bots.
  • At least 24 Mexican financial entities, including local and international banks, have been targeted.
  • The modular design of the phishing kit allows threat actors to easily adapt and target new institutions, making takedowns challenging.

GitBait: Sophisticated Phishing Targets Mexican Financial Sector via GitHub Pages

A highly organized phishing operation, dubbed “GitBait,” is actively compromising the financial sector in Mexico, demonstrating an advanced level of precision rarely seen in credential theft campaigns. This persistent threat has been quietly evolving for over three years, utilizing a stealthy approach to deceive victims.

Table Of Content

  • Key Takeaways
  • GitBait: Sophisticated Phishing Targets Mexican Financial Sector via GitHub Pages
  • Exploiting GitHub Pages for Trust and Evasion
  • Centralized Credential Theft Through SheetBest API
  • What You Should Do

The GitBait campaign leverages GitHub Pages, a widely recognized and trusted free hosting service, to deploy meticulously crafted fake banking portals. These malicious sites are nearly indistinguishable from legitimate financial institution websites, tricking users into divulging sensitive information such as login credentials and payment card details without suspicion. Details of the campaign were released in a recent report.

Analysis of historical infrastructure indicates the GitBait campaign has maintained continuous activity for more than three years, consistently refining its tactics and expanding its list of targets. The operation has successfully aimed at a minimum of 24 financial institutions operating within Mexico, encompassing both indigenous banks and foreign entities with a local presence.

Security researchers at Group-IB discovered the campaign, noting its fully serverless architecture. This innovative setup routes stolen credentials through SheetBest, a third-party API service, directly into Google Sheets controlled by the attackers in real-time. Group-IB’s report, shared with Cyber Security News (CSN), highlights the modular nature of the GitBait infrastructure, which enables threat actors to quickly swap phishing templates and target new institutions without requiring a complete rebuild of their operational setup.

More than 200 domains have been linked to this extensive campaign. Each domain hosts multiple phishing pages under directory paths such as “cancelacion,” “soporte,” and “mbw,” designed to mimic legitimate banking service categories. These specific directory structures also aid the operation in evading automated detection systems that rely on established lists of malicious domains. Furthermore, the phishing pages are optimized for seamless display on both desktop and mobile devices, indicating a deliberate strategy to maximize victim engagement across all platforms. The credential harvesting scheme operates without the need for a traditional command-and-control server.

In at least one documented instance, an alternative exfiltration method was observed, where victim data was sent in real-time to a Telegram bot. This was achieved through hardcoded tokens and chat IDs embedded within the page’s JavaScript. The ongoing maintenance and evolution of the campaign are evident through commit histories across multiple GitHub repositories, suggesting a collaborative and actively managed group of operators behind GitBait.

Exploiting GitHub Pages for Trust and Evasion

The core of the GitBait operation’s success lies in its exploitation of GitHub Pages. This platform’s inherent trustworthiness and default HTTPS coverage mean that many automated security tools do not flag hosted content as suspicious. Threat actors capitalize on this trust to deploy phishing pages that bypass standard blocklist checks, reaching their intended targets more effectively.

Each GitHub repository associated with the campaign contains duplicated phishing content under various directory paths. This redundancy makes takedowns challenging, as removing one specific path does not eliminate other active phishing instances. The phishing kit incorporates an internal campaign selector, allowing operators to choose which bank to impersonate and then generate a corresponding fraudulent URL.

The impersonation landing pages meticulously replicate the visual identity, layout, and navigation of legitimate banking portals. This high fidelity creates a false sense of security before victims are directed to credential-harvesting forms. These forms collect critical information, including usernames, passwords, customer IDs, and payment card details, through a multi-stage process designed to mimic a genuine online banking session.

Centralized Credential Theft Through SheetBest API

Upon a victim’s submission of their information, client-side JavaScript code intercepts the form data before it is processed by the browser. The stolen data is then serialized into JSON format and dispatched via a POST request to the SheetBest API, which directly populates an attacker-controlled Google Sheet. This serverless model significantly reduces the need for costly backend infrastructure, thereby lowering operational expenses and making attribution considerably more difficult for defenders.

Group-IB has proactively reported all identified phishing pages and domains to GitHub. Financial institutions are strongly advised to implement proactive monitoring for GitHub Pages repositories that attempt to impersonate their brand. Specific naming patterns to watch for include “brand-soporte” or “brand-cancelacion.”

What You Should Do

  • Proactive Monitoring: Financial institutions should actively monitor GitHub Pages for repositories impersonating their brand using patterns like “brand-soporte” or “brand-cancelacion.”
  • Network Traffic Analysis: Track unexpected outbound POST requests to api.sheetbest[.]com from user-facing web sessions to detect credential exfiltration.
  • Enhanced Customer Protection: Implement behavioral detection mechanisms and real-time transaction alerts to protect customers even if their credentials are compromised.
  • Employee Training: Conduct regular security awareness training for employees to recognize sophisticated phishing attempts, especially those leveraging trusted domains.
  • Threat Intelligence Sharing: Share threat intelligence with peer institutions and regulatory bodies to facilitate a coordinated and rapid response across the financial sector.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain soporte-index.github[.]io GitHub Pages phishing domain
Domain soporte-index69.github[.]io GitHub Pages phishing domain
Domain sntdr-soporte.github[.]io GitHub Pages phishing domain
Domain v9-soporte.github[.]io GitHub Pages phishing domain
Domain soporte169.github[.]io GitHub Pages phishing domain
Domain soporte1505.github[.]io GitHub Pages phishing domain
Domain soporte16032k.github[.]io GitHub Pages phishing domain
Domain soporte96.github[.]io GitHub Pages phishing domain
Domain soporte-bmw.github[.]io GitHub Pages phishing domain
Domain soporte-r2.github[.]io GitHub Pages phishing domain
Domain api.sheetbest[.]com SheetBest API used for credential exfiltration
Domain soporte5014.github[.]io GitHub Pages phishing domain
Domain soporte15052014.github[.]io GitHub Pages phishing domain
Domain soporte20032k.github[.]io GitHub Pages phishing domain
Domain soporte250.github[.]io GitHub Pages phishing domain
Domain soporte-index69.github[.]io GitHub Pages phishing domain
Domain soporte-bnw.github[.]io GitHub Pages phishing domain
Domain fldsmdrc-95.github[.]io GitHub Pages phishing domain
Domain soporte-bx.github[.]io GitHub Pages phishing domain
Domain soporte-index.github[.]io GitHub Pages phishing domain
Domain soporte-cw.github[.]io GitHub Pages phishing domain
Domain soporte-bk.github[.]io GitHub Pages phishing domain
Domain sntdrsoporte-jatencionf.github[.]io GitHub Pages phishing domain
Domain soporte-jatencionf.github[.]io GitHub Pages phishing domain
Domain soporte-j-atencion.github[.]io GitHub Pages phishing domain
Domain soporte-bh.github[.]io GitHub Pages phishing domain
Domain respaldo95.github[.]io GitHub Pages phishing domain
Domain soporte-indexg1.github[.]io GitHub Pages phishing domain
Domain gnilsoporte.github[.]io GitHub Pages phishing domain
Domain soporte-gn-il.github[.]io GitHub Pages phishing domain
Domain soporte-gnil.github[.]io GitHub Pages phishing domain
Domain goil-soporte.github[.]io GitHub Pages phishing domain
Domain gnil-soporte.github[.]io GitHub Pages phishing domain
Domain soporte-sh.github[.]io GitHub Pages phishing domain
Domain soportecgj.github[.]io GitHub Pages phishing domain
Domain support-gh.github[.]io GitHub Pages phishing domain
IP Address 176.97.214[.]92 Remote address for SheetBest API credential submission
Operator Account ss-soporte (GitHub) rronromoBgmail[.]com — Initial repository setup and base infrastructure creation
Operator Account ce-soporte (GitHub) jejcgsbsbs Bgmail[.]com — Activation of GitHub Pages hosting
Operator Account soporte-swjejcgsbsbsBgmail[.]com (GitHub) Addition of new institution templates and removal of others
Operator Account soporte-BRAND-NAMEB-soperte (GitHub) hig3naarool101Bgmail[.]com — Updates to credential harvesting pages
File Hash (CSS) sha256 bootstrap v5.3.0-alpha1 CSS SHA256 hash (see report) Bootstrap CSS SRI hash used across phishing pages
File Hash (JS) sha256 bootstrap v5.3.0-alpha1 JS SHA256 hash (<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/34c54cfb-6468-4308-a894-abac1fa7acb9/GitBait-Phishing-Campaign-Abuses-GitHub-Pages-to-Attack-Financial-Institutions.pdf?AWSAccessKeyId=ASIA2F3EMEYEVVFW6FD6&Signature=hLGXItcflhwKrL3Dbav5n1MB%2Fbs%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIFPGrdAApUOVnZYyriVzvyxynWn63REqtFxxUojUqcHbAiBRX8ipM0ANNPmr3G75n76C5EIjOQqF5ZeopSGaYKyLcyr8BAiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMvnMFg%2BACP1k7lBeCKtAEljoH%2BZvuvP%2Fwk0iiiJEHoVI71JWuNRVbi12n%2BXIw1KUWbKMPspwNn3Jd6ttqYlPdAaXdkr2oBbR4CbiQcEDLiFIybgS4UM0srdsQQrIO9DpxqbgFaj2sgsDQWFQ47hMf6ocOI0uXJbCqW1gAYpT7XJ7fYS8VJcbrnplBXaYGKkPNuVnqE5UdXJCyOBUYRologwR77V0ESd3TR35rTShCPc68fKBLF46cOvDdlWlf0QUvX1h%2F%2Bb9%2F04tk4ck69AmAhJc5OKI%2BDMq2s

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitphishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Fake macOS Software Updates Steal Passwords, Crypto Wallet Data

Next Post

Critical Microsoft ClickOnce flaw lets attackers install malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical IBM SPSS Vulnerability Lets Attackers Deploy CNCMachineRMS RAT
August 12, 2026
Top Network Access Control (NAC) Solutions for 2026
August 12, 2026
Critical Microsoft SharePoint Server CVE-2023-29357 Lets Attackers Remotely Execute Code
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us