
A phishing operation dubbed GitBait has been targeting customers of at least twelve Mexican banks by hosting fake login pages on GitHub Pages, according to research published by Group-IB. Group-IB
The attackers clone legitimate bank portals and deploy them through GitHub Pages, using the SheetBest API to capture entered credentials in real time and store them in Google Sheets. Infosecurity Magazine notes that over one hundred domains have been created to support the effort, with a modular phishing kit allowing rapid reproduction of each brand’s look and feel.
Victims are lured via SMS and social media messages that display branded previews, directing them to the fraudulent sites where their usernames, passwords and sometimes one‑time codes are harvested. SecurityOnline reports that the campaign has been active for roughly three years, yet no specific vulnerabilities or CVE identifiers have been linked to the infrastructure.
Although the operators remain unattributed, their activity is described as financially motivated and persistent, leveraging the trust placed in reputable cloud services to evade traditional blocklists. Group‑IB stresses that simple IP or URL blocking has proven ineffective because the malicious pages constantly rotate across newly generated GitHub‑hosted addresses.
Defenders should prioritise monitoring for brand abuse on platforms such as GitHub Pages and SheetBest, establishing takedown procedures with those providers and employing behavioural analytics to detect anomalous login patterns. Infosecurity Magazine also recommends reinforcing customer education about unexpected links in messages and encouraging the adoption of phishing‑resistant multi‑factor authentication wherever possible.
Additionally, security teams can enrich threat‑intelligence feeds with the observed domain patterns and share indicators of compromise with industry‑specific ISACs to accelerate detection across institutions. SecurityOnline concludes that a layered approach combining proactive brand protection, user awareness and adaptive authentication offers the best chance to blunt the impact of campaigns like GitBait.