# Operation HookedWing: A Persistent Phishing Campaign Targeting 500+ Organizations Across Critical Sectors


## The Threat


A sophisticated phishing campaign dubbed Operation HookedWing has compromised credentials from more than 500 organizations over a sustained four-year period, with 2,000+ user accounts falling victim to the coordinated attack. The campaign, documented by threat intelligence firm SOCRadar, demonstrates the persistence and adaptability of modern credential harvesting operations targeting organizations with access to sensitive infrastructure and high-privilege systems.


The threat actor behind Operation HookedWing operates with remarkable operational security and tactical sophistication, maintaining active command-and-control infrastructure across multiple platforms while continuously evolving their lures and delivery mechanisms. Analysis of the campaign reveals deliberate targeting of organizations with geopolitical significance—a pattern that suggests the operation may be sponsored by a nation-state or well-resourced threat collective.


## Background and Context


Operation HookedWing first emerged in 2022 but has maintained continuous activity over the subsequent four-year period, adapting its tactics while preserving its core operational methodology. The campaign's longevity and resilience indicate that the underlying infrastructure and organizational capabilities have withstood disruption efforts and competitive pressure from other threat actors.


### Timeline of Evolution


| Period | Key Characteristics | Infrastructure |

|--------|-------------------|-----------------|

| 2022-2024 | English-language content, Microsoft/Outlook themes | GitHub domains, compromised servers |

| 2024-2025 | French-language expansion, sustained targeting | GitHub + other platforms, continued server compromises |

| 2025-Present | Expanded infrastructure, obfuscated domain naming, additional themes | 2+ dozen C&C servers, 100+ GitHub domains, multiple distribution vectors |


The phishing campaign has successfully targeted organizations across multiple strategic sectors:


  • Aviation and travel
  • Critical infrastructure
  • Energy sector
  • Financial services
  • Government agencies
  • Logistics and supply chain
  • Public administration
  • Technology companies

  • ## Technical Details: How the Attack Works


    Operation HookedWing relies on a deceptively simple yet effective phishing methodology. The attack begins with targeted emails impersonating human resources departments, colleagues, or system notifications. These messages are carefully crafted to convey authority and urgency without triggering security awareness protocols.


    ### Delivery and Infection Chain


    The initial phishing emails contain links pointing to GitHub repositories or intermediary hosting platforms. When victims click these links, they are redirected to fraudulent landing pages that impersonate Microsoft Outlook login interfaces.


    The technical sophistication lies in the psychological manipulation employed:


    1. Credibility Building: The landing page displays a full-screen pre-loader animation

    2. Personalization: The loading screen and login form reference the victim's organization name or details from the original phishing email

    3. Behavioral Reinforcement: Seeing their own organization name on the loading screen significantly increases the victim's confidence in the interface

    4. Credential Harvesting: Once the victim enters their credentials, a background script simultaneously:

    - Captures email address and password

    - Records source IP address and full geolocation data

    - Identifies the victim's organization domain

    - Logs the source URL referrer


    ### Infrastructure Scale


    SOCRadar's analysis identified:


  • 24+ command-and-control servers coordinating the campaign
  • 100+ GitHub domains used for phishing page hosting
  • Dozen+ distribution domains on alternative platforms
  • Multiple obfuscation techniques employed in domain naming conventions

  • The use of GitHub as a primary infrastructure component is particularly noteworthy, as it provides legitimate hosting that is harder to distinguish from benign traffic and complicates takedown efforts.


    ## Targeting Patterns and Geopolitical Significance


    Analysis of victim selection reveals the campaign is not opportunistic but highly targeted. SOCRadar identified a clear pattern: "Victim selection suggests a particular interest in environments with access to sensitive information, critical operations, or high-privilege credentials that can be sold or used by other adversaries."


    The geopolitical nature of targeted organizations—particularly in critical infrastructure, energy, and government sectors—combined with the expansion of French-language lures in 2024-2025, suggests the threat actor is either:


  • Operating on behalf of a nation-state with geographic or geopolitical interests
  • Supplying credentials to nation-state actors or intelligence agencies
  • Conducting pre-positioning for future cyber operations against strategic targets

  • The deliberate targeting of aviation, energy, and critical infrastructure sectors is particularly concerning, as compromised credentials within these domains could enable severe disruption.


    ## Evolution and Adaptation


    The campaign's four-year operational history reveals a threat actor that learns from the threat landscape and adapts tactics accordingly:


  • Linguistic Expansion: Adding French-language phishing emails in 2024 suggests geographic expansion or targeting of French-speaking organizations
  • Infrastructure Diversification: Moving beyond GitHub-only hosting to multiple platforms reduces exposure to single-platform takedowns
  • Domain Obfuscation: Increasingly complex GitHub domain naming conventions make automated detection more difficult
  • Lure Variation: Expanding themes beyond Microsoft/Outlook to multiple impersonation scenarios increases the probability of success

  • ## Implications for Organizations


    The sustained success of Operation HookedWing carries significant implications:


    ### Credential Compromise Risk


    Every compromised credential represents a potential entry point for follow-on attacks. The gathered geolocation and IP data also provide attackers with contextual information about the victim's location and network environment.


    ### Supply Chain and Secondary Targeting


    The sale or sharing of harvested credentials with other threat actors means a single phishing success can trigger multiple downstream attacks from different adversaries.


    ### Critical Infrastructure Vulnerability


    Organizations in aviation, energy, and infrastructure sectors should understand that credentials harvested from their networks may be actively used in offensive cyber operations.


    ### Detection Challenges


    The campaign's longevity suggests that traditional email security controls, user awareness training, and credential protection measures have proven insufficient against this threat actor's sophistication and persistence.


    ## Recommendations for Defenders


    Organizations targeted by Operation HookedWing or operating in similar sectors should implement:


  • Multi-Factor Authentication (MFA): Mandatory on all accounts with access to critical systems or sensitive data
  • Conditional Access Policies: Restrict logins from unusual geographic locations or IP ranges
  • Email Authentication: Implement SPF, DKIM, and DMARC to reduce email spoofing
  • Credential Guard: Utilize OS-level credential protection mechanisms
  • Behavioral Analytics: Deploy tools that detect unusual credential usage patterns
  • Incident Response Planning: Prepare for scenarios where credentials may have been compromised
  • Threat Intelligence Sharing: Participate in information sharing about Operation HookedWing indicators

  • ---


    ## HackWire Analysis


    Operation HookedWing represents a fundamental challenge to modern cybersecurity defenses: the phishing email remains devastatingly effective despite decades of awareness training and email security investment. What makes this campaign particularly concerning is not technical innovation—the attack methodology is relatively straightforward—but rather the systematic patience and operational discipline of the threat actor.


    The four-year operational window and the targeting of geopolitically sensitive organizations suggests this is not a typical cybercrime operation. Credential harvesting campaigns are typically monetized through rapid sale on underground forums, followed by quick takedown cycles. Operation HookedWing's persistence, selective targeting, and infrastructure investment pattern all point toward nation-state involvement or state-sponsored activity.


    The expansion into French-language phishing in 2024-2025 is particularly revealing. This suggests either a shift in geographic targeting toward French-speaking regions and organizations, or deliberate obfuscation to create attribution ambiguity. Either way, it indicates an actor with:


    1. Multi-language operational capability (English, French, presumably others)

    2. Sufficient resources to maintain 2+ dozen C&C servers long-term

    3. Patience for sustained operations that may not show immediate returns

    4. Understanding of critical infrastructure sectors to select high-value targets


    For defenders, the lesson is sobering: awareness training and email filters cannot stop a motivated, patient, well-resourced actor willing to operate for four years to build credential inventories of strategic targets. The real defense is layered security requiring multiple authentication factors, behavioral analytics to detect compromised credentials in use, and preparation for inevitable credential compromise.


    Organizations in aviation, energy, and critical infrastructure should treat credential compromise as a "when, not if" scenario and architect their security accordingly. The operators of Operation HookedWing are patient. They will wait for the right moment to activate harvested credentials when maximum damage can be achieved.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)