APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via
Source: The Hacker News · August 28, 2026 at 10:01 AM · AI-assisted report
Single-sourceKUALA LUMPUR, 28 AUGUST 2026 —
CYBERSECURITY: RUSSIAN HACKERS DEPLOY NEW HOOKEDGE BACKDOOR IN EUROPEAN GOVERNMENT ATTACKS
Market Impact
KUALA LUMPUR, Aug 28 — Cybersecurity firm Recorded Future’s Insikt Group has uncovered a series of cyberattacks targeting government and diplomatic entities in Romania, Spain, and Türkiye between late September 2025 and early April 2026. The campaigns involved a previously undocumented backdoor named HOOKEDGE, a lightweight Windows batch script distributed via macro-enabled Microsoft Word documents with diplomatic-themed lures.
The activity has been attributed with moderate confidence to APT28 (also known as Fancy Bear and Forest Blizzard), a Russian state-sponsored hacking group tracked by Recorded Future under the alias BlueDelta. The attribution is based on significant code and tradecraft overlaps with HEADLACE, a modular Windows backdoor previously used by APT28 in attacks on diplomats since April 2023.
HOOKEDGE’s delivery mechanism involves a malicious Word document that prompts victims to enable macros, triggering the execution of an installer chain. This chain creates a scheduled task running every 30 minutes to launch the HOOKEDGE backdoor, which then deletes itself and related files to minimize forensic traces. The malware uses webhook[.]site services for command-and-control (C2), payload staging, and data exfiltration, blending malicious traffic with legitimate network activity.
The backdoor operates in a polling loop, fetching arbitrary .cmd payloads from a staging webhook, executing them, and sending output back via an HTML file. It leverages Microsoft Edge in headless mode for these operations and terminates temporary files and processes linked to its task identifier after data transmission. For high-value targets, BlueDelta deploys a second-stage HOOKEDGE payload with a beaconing interval as short as five minutes to enhance operational control.
The attackers have refined HOOKEDGE’s architecture to evade automated sandbox environments and adapt to webhook[.]site’s free-tier API limits, which cap requests at 100 per endpoint. By separating initial-access and active-collection infrastructure, BlueDelta ensures sustained access without prematurely exhausting endpoint quotas. The group has also removed document-open canaries that previously captured victim IP addresses, likely to reduce network-based indicators of compromise.
For Malaysian organizations, the emergence of HOOKEDGE underscores the need for robust cybersecurity measures. Experts recommend blocking macro execution from internet-originated documents and implementing detection for scheduled task abuse, headless Edge execution, and outbound connections to webhook services. BlueDelta’s continuous refinement of existing tooling highlights the group’s focus on operational resilience rather than novel capabilities.
The evolving tactics of APT28-linked groups pose a persistent threat to government and diplomatic targets across Europe and beyond. As cyber espionage operations grow more sophisticated, organizations must prioritize proactive threat detection and response to mitigate risks associated with lightweight, adaptable malware like HOOKEDGE.
Related: Kuala Lumpur