Malicious Phishing Data Exfiltration to SheetBest API by GitBait Campaign (via proxy)

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule detects HTTP POST requests to the api.sheetbest.com sheets endpoint used by the GitBait phishing campaign to exfiltrate stolen banking credentials from GitHub Pages lures. The campaign abuses the SheetBest Google Sheets API as a low-cost data drop for harvested victim data. Detecting these calls surfaces active credential exfiltration.

Related detections9 linkedT1071.001 — drag to rearrange
Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Suspicious CurKeep Backdoor C2 API Endpoints (via proxy)
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Windows Process Execution of Common Tunneling Tools (httptunnel, plink, socat, stunnel)
Suspicious AdaptixC2 Beacon Status Request by JadeProx TriBack Loader (via proxy)
Suspicious HTTP Beacon with Java Agent User-Agent (via proxy)
Possible GoldFactory GoldPickaxe Mobile Trojan C2 API Calls
Suspicious Telegram Bot API getUpdates Polling for C2 by Millenium RAT (via proxy)
Malicious Phishing Data Exfiltration to SheetBest API by GitBait Campaign (via proxy)
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.