This is not a one-off phishing wave. Operation HookedWing has stayed effective for four-plus years by changing infrastructure and lure language without changing its core pattern, so taking down a few domains or filtering English-only Microsoft/Outlook bait does not break the campaign.
SOCRadar says the operation has stolen more than 2,000 credentials from over 500 organizations across aviation, critical infrastructure, energy, logistics, public administration, government, financial services, and technology. It has used GitHub domains, compromised servers, and, in 2024–25, French content alongside the earlier English lures.
The risk is persistent credential theft at scale, not just another set of bad links. That creates account takeover and downstream BEC exposure even after individual pages disappear, because the actor keeps rotating infrastructure and expanding lure themes.