Over 500 Organizations Hit in Years-Long Phishing Campaign

https://www.securityweek.com/wp-content/uploads/2025/11/AI-phishing.jpeg

A phishing campaign that has been ongoing for more than four years has made hundreds of victims across multiple industries, SOCRadar reports.

Dubbed Operation HookedWing, the campaign was first documented in 2022 but has sustained activity and adapted its infrastructure while keeping core patterns largely unchanged.

Over the course of four years, more than 2,000 user credentials across over 500 organizations in the aviation and travel, critical infrastructure, energy, financial, government, logistics, public administration, and technology sectors were stolen as part of the campaign.

Between 2022 and 2024, Operation HookedWing used GitHub domains with English content and compromised servers as infrastructure, and the attacks mainly featured Microsoft and Outlook themes.

In 2024 and 2025, the threat actor expanded its targeting with French content, continuing to use GitHub, compromised servers, and previously observed phishing themes.

Starting in 2025, the threat actor has expanded both the active infrastructure and lures, obfuscating...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE