An ongoing campaign, active since 2017, has been stealing credentials via global DNS hijacking attacks.
Source: Threadpost