logo

Operation HookedWing: 4-Year Multi-Sector Attack Analysis

ID: b66f68e0-4cc7-5430-8547-24629724d9b5

STIX ID: report--b66f68e0-4cc7-5430-8547-24629724d9b5

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ameer Owda

...
...

Operation HookedWing is a long-running, multi-variant phishing campaign that leverages legitimate static hosting (primarily GitHub Pages) to present benign-looking loaders which dynamically inject credential-harvesting forms from attacker-controlled PHP backends hosted on compromised or adversary-registered servers; the kit extracts victim emails via URL fragments, collects geolocation via ipdata.co, forces retry cycles to improve credential capture, and has impacted over 2,500 unique victims across 500+ organizations with clear targeting of aviation, government, and energy sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.