4-year phishing operation compromises 2,000 credentials from 500 organizations across aviation, government, and energy sectors using GitHub-hosted landing pages and compromised C2 infrastructure.
Operation HookedWing technical breakdown:
• Custom phishing kit uses github[.]io domains with email in URL fragment (
@domain[.]com) to bypass server logging
• Dynamic PHP injection from compromised C2s under /genl/ path - form never stored on distribution layer
• Targets aviation corridors linking Africa 🇳🇬 🇺🇬 🇸🇳, Persian Gulf, and South Asia 🇳🇵 🇱🇰 with 28% victims in aviation/travel sector
• Multi-stage evasion: preloader_container_stef namespace, base64-encoded C2 paths in window.stef.srv_loc, fake error forcing credential re-entry
Attack chain spans 4 campaigns sharing infrastructure:
• HR/Microsoft/Google lures → GitHub landing page → geolocation via ipdata[.]co API → dynamic form injection from /genl/[random].php
• Persistence through indefinite GitHub page reactivation by updating srv.js
• 22 compromised domains across Pakistan 🇵🇰, Brazil 🇧🇷, Chile 🇨🇱, Senegal 🇸🇳, Afghanistan 🇦🇫 hosting credential logs in list.txt
Hunt for GitHub repos with "preloader_container_stef" class, outbound requests to /genl/ endpoints, and ipdata[.]co API calls from corporate networks. Full IOC list available in report.
#DFIR_Radar