Researchers disclosed two large phishing operations that used legitimate or compromised infrastructure to impersonate trusted brands and harvest victim data at scale. Group-IB said the GitBait campaign targeted at least 24 financial institutions in Mexico over more than three years by abusing GitHub Pages to host fake banking portals across more than 200 domains. The kit used client-side JavaScript to capture credentials and exfiltrate them through the SheetBest API into attacker-controlled Google Sheets, while at least one variant also forwarded data to a Telegram bot. Investigators said the modular phishing kit supported desktop and mobile devices and included an internal selector to switch between bank brands, complicating detection and takedown efforts.
A separate campaign targeted millions of UK shoppers with fake Boots emails promising a free beauty sample pack and directing victims to a bogus survey and checkout page hosted on a compromised Bolivian government website. Researchers linked that activity to Romanian threat actors and found the emails were sent with Gammadyne Mailer installed on a compromised UK business terminal server, masking the operation behind the victim organization's internet connection. The same toolkit has reportedly appeared on multiple compromised systems since July 2025 and has also been used in tax-themed and cryptocurrency lures, underscoring a broader effort to exploit trusted brands, public-sector websites, and hijacked business infrastructure for credential and personal-data theft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers attributed the Boots-themed phishing operation to Romanian threat actors. They also found the emails were sent using Gammadyne Mailer on a compromised UK business terminal server to mask the attackers behind the victim organization’s internet connection.
Attackers sent fake Boots emails to millions of UK shoppers offering a free beauty sample pack. The campaign sought personal information through a bogus survey and a fraudulent checkout page hosted on a compromised Bolivian government website.
Group-IB reported the identified GitBait phishing pages and domains to GitHub. The company also advised financial institutions to watch for GitHub Pages brand impersonation and suspicious POST requests to api.sheetbest.com.
Group-IB said the GitBait phishing campaign has operated for more than three years, targeting Mexico’s financial sector. The campaign has impersonated at least 24 financial institutions and used more than 200 domains hosted via GitHub Pages.
Researchers found the same phishing toolkit used in the fake Boots campaign on multiple compromised systems since July 2025. They said the broader activity also included tax-themed and cryptocurrency scams targeting UK consumers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.