News Article · Jun 17, 2026 at 4:11 PM
2 min read 0
Member
Serverless Phishing, Android Trojan, and Cisco Bugs Mark a Busy Week in Cyber Threats
Security #phishing #Cisco #SD-WAN #GitBait #Rokarolla #Android trojan #account takeover #Group-IB #Zimperium

Serverless Phishing, Android Trojan, and Cisco Bugs Mark a Busy Week in Cyber Threats

A new serverless phishing kit called GitBait abuses GitHub Pages and SheetBest to steal Mexican banking credentials, while the Rokarolla Android trojan targets 217 banking and crypto apps. Cisco also updates a max-severity bug advisory.

Listen to this article 3 min

A long-running phishing operation dubbed GitBait has abused GitHub Pages and a legitimate data service called SheetBest to steal banking credentials from customers of at least 12 Mexican financial institutions, according to new analysis from Group-IB. The campaign, which ran for roughly three years without its own server infrastructure, hosted fake bank pages on GitHub Pages and funneled stolen logins through SheetBest, which writes data directly into Google Sheets.

Group-IB identified more than 100 GitHub-hosted domains tied to the campaign, each serving several phishing pages. The modular kit included a desktop and mobile operator panel that let attackers pick a target bank and generate a matching fake page. Commit records on one repository showed 66 commits, indicating active development, with three contributor accounts sharing an email address and automated publishing via Jekyll and GitHub Actions.

Android Trojan Rokarolla Targets 217 Banking and Crypto Apps

Separately, researchers at Zimperium discovered a new Android banking trojan named Rokarolla that targets 217 banking and cryptocurrency applications and can execute 137 distinct commands on infected devices. The malware is primarily distributed through malicious websites that impersonate popular apps such as TikTok and Google Chrome.

  • Rokarolla is named after its command-and-control infrastructure, according to Zimperium.
  • The trojan enables device takeover capabilities, allowing attackers to perform actions including intercepting SMS messages and initiating fraudulent transactions.
  • It requests accessibility service permissions to overlay fake login screens and capture credentials.
  • Affected applications span multiple countries and include major banks and crypto exchanges.
  • Zimperium recommends users avoid sideloading apps and verify app permissions carefully.

Account Takeover Threats and Cisco SD-WAN Vulnerabilities

Account takeovers are on the rise as attackers bypass traditional defenses through phishing, session hijacking, and MFA fatigue attacks, Specops Software warned in a recent analysis. The firm recommends device trust and continuous verification to reduce risk, rather than relying solely on username and password authentication.

Cisco also updated a max-severity security advisory to include an additional SD-WAN device model. The vulnerability, which affects Cisco SD-WAN vEdge routers, could allow an unauthenticated attacker to execute arbitrary code on affected devices. Cisco urged customers to review their devices and apply available patches. These developments underscore a growing trend where attackers increasingly rely on trusted cloud services and commodity malware kits rather than custom infrastructure, making detection harder for traditional blocklists.

Fact check

  • GitBait campaign targeted at least 12 Mexican financial institutions over three years.

    reported · source

  • Rokarolla Android trojan targets 217 banking and cryptocurrency applications.

    reported · source

  • Cisco added another SD-WAN box to max-severity bug advisory.

    reported · source

Source reporting (10)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 114 users online: 0 registered, 107 guests and 7 bots.

Most users ever online was 1,755 on 17 Jun 2026, 5:11 pm.

Bots: AhrefsBot Applebot Bingbot Facebook Other Bot SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 356