Skip to content
Breaking
How the Sales and Purchase Agreement worksWhy Asia’s inflation scare may be overstated: a Morgan Stanley economist explainsNebal-Tibet disaster: Flood rescue operations resume after brief suspensionAPT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations‘Buying opportunity’: Sembcorp’s India unit IPO could lift group value by up to 10%PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF VersionsIndonesian Stocks End Week Lower as Investors Await Fed SignalsBNPB DSP, Health Ministry: Medical costs for NTT earthquake victims freeAvaland posts 41% quarterly net profit rise after strong salesIndonesia urges community-led reconstruction for quake-hit NTT homesBelgian startup Any raises €10 million for production of LUV1 electric motorcycleRoad accidents and injuries rise in first half of 2026 despite fewer deathsMah Sing lifts 2Q net profit 9.8% as revenue jumps 16%Startup community gathers in New York on September 10 to debate AI-driven business modelsWe need to decide if the given headline is already fluent natural English. The headline: "No, Mark Zuckerberg, the future is not (yet) for everyone". This seems a bit odd: "No, Mark Zuckerberg, the future is not (yet) for everyone". It reads like a response to Mark Zuckerberg? The phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is somewhat awkward. Usually you'd say "No, Mark Zuckerberg, the future is not yet for everyone" or "No, Mark Zuckerberg: the future is not (yet) for everyone". The parentheses around "yet" maybe okay. But the phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is a bit unnatural. It could be interpreted as addressing Mark Zuckerberg: "No, Mark Zuckerberg, the future is not (yet) for everyone". That is a direct address, but the comma after Zuckerberg is correct for direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone". Actually direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone." That is grammatical: youVirtual power plant pilot in Malaysia serves fewer than 1,000 households after three yearsMalaysia Secures RM218.5 Billion Approved Investments in 1H 2026, Jobs Rise 8.4%Import tariff transmission in a production network | Makram Khalil, Pierre M. Rouillard, Felix StrobelIndonesia’s growth outlook holds despite global headwindsPSE wraps 2026 mid-year STAR investor briefing with 13 live presentationsHow the Sales and Purchase Agreement worksWhy Asia’s inflation scare may be overstated: a Morgan Stanley economist explainsNebal-Tibet disaster: Flood rescue operations resume after brief suspensionAPT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations‘Buying opportunity’: Sembcorp’s India unit IPO could lift group value by up to 10%PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF VersionsIndonesian Stocks End Week Lower as Investors Await Fed SignalsBNPB DSP, Health Ministry: Medical costs for NTT earthquake victims freeAvaland posts 41% quarterly net profit rise after strong salesIndonesia urges community-led reconstruction for quake-hit NTT homesBelgian startup Any raises €10 million for production of LUV1 electric motorcycleRoad accidents and injuries rise in first half of 2026 despite fewer deathsMah Sing lifts 2Q net profit 9.8% as revenue jumps 16%Startup community gathers in New York on September 10 to debate AI-driven business modelsWe need to decide if the given headline is already fluent natural English. The headline: "No, Mark Zuckerberg, the future is not (yet) for everyone". This seems a bit odd: "No, Mark Zuckerberg, the future is not (yet) for everyone". It reads like a response to Mark Zuckerberg? The phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is somewhat awkward. Usually you'd say "No, Mark Zuckerberg, the future is not yet for everyone" or "No, Mark Zuckerberg: the future is not (yet) for everyone". The parentheses around "yet" maybe okay. But the phrase "No, Mark Zuckerberg, the future is not (yet) for everyone" is a bit unnatural. It could be interpreted as addressing Mark Zuckerberg: "No, Mark Zuckerberg, the future is not (yet) for everyone". That is a direct address, but the comma after Zuckerberg is correct for direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone". Actually direct address: "No, Mark Zuckerberg, the future is not (yet) for everyone." That is grammatical: youVirtual power plant pilot in Malaysia serves fewer than 1,000 households after three yearsMalaysia Secures RM218.5 Billion Approved Investments in 1H 2026, Jobs Rise 8.4%Import tariff transmission in a production network | Makram Khalil, Pierre M. Rouillard, Felix StrobelIndonesia’s growth outlook holds despite global headwindsPSE wraps 2026 mid-year STAR investor briefing with 13 live presentations
AI Edge

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via

Source: The Hacker News · August 28, 2026 at 10:01 AM · AI-assisted report

Single-source
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Photo: CEphoto, Uwe Aranas / CC BY-SA 3.0

KUALA LUMPUR, 28 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

CYBERSECURITY: RUSSIAN HACKERS DEPLOY NEW HOOKEDGE BACKDOOR IN EUROPEAN GOVERNMENT ATTACKS

Market Impact

KUALA LUMPUR, Aug 28 — Cybersecurity firm Recorded Future’s Insikt Group has uncovered a series of cyberattacks targeting government and diplomatic entities in Romania, Spain, and Türkiye between late September 2025 and early April 2026. The campaigns involved a previously undocumented backdoor named HOOKEDGE, a lightweight Windows batch script distributed via macro-enabled Microsoft Word documents with diplomatic-themed lures.

The activity has been attributed with moderate confidence to APT28 (also known as Fancy Bear and Forest Blizzard), a Russian state-sponsored hacking group tracked by Recorded Future under the alias BlueDelta. The attribution is based on significant code and tradecraft overlaps with HEADLACE, a modular Windows backdoor previously used by APT28 in attacks on diplomats since April 2023.

HOOKEDGE’s delivery mechanism involves a malicious Word document that prompts victims to enable macros, triggering the execution of an installer chain. This chain creates a scheduled task running every 30 minutes to launch the HOOKEDGE backdoor, which then deletes itself and related files to minimize forensic traces. The malware uses webhook[.]site services for command-and-control (C2), payload staging, and data exfiltration, blending malicious traffic with legitimate network activity.

The backdoor operates in a polling loop, fetching arbitrary .cmd payloads from a staging webhook, executing them, and sending output back via an HTML file. It leverages Microsoft Edge in headless mode for these operations and terminates temporary files and processes linked to its task identifier after data transmission. For high-value targets, BlueDelta deploys a second-stage HOOKEDGE payload with a beaconing interval as short as five minutes to enhance operational control.

The attackers have refined HOOKEDGE’s architecture to evade automated sandbox environments and adapt to webhook[.]site’s free-tier API limits, which cap requests at 100 per endpoint. By separating initial-access and active-collection infrastructure, BlueDelta ensures sustained access without prematurely exhausting endpoint quotas. The group has also removed document-open canaries that previously captured victim IP addresses, likely to reduce network-based indicators of compromise.

For Malaysian organizations, the emergence of HOOKEDGE underscores the need for robust cybersecurity measures. Experts recommend blocking macro execution from internet-originated documents and implementing detection for scheduled task abuse, headless Edge execution, and outbound connections to webhook services. BlueDelta’s continuous refinement of existing tooling highlights the group’s focus on operational resilience rather than novel capabilities.

The evolving tactics of APT28-linked groups pose a persistent threat to government and diplomatic targets across Europe and beyond. As cyber espionage operations grow more sophisticated, organizations must prioritize proactive threat detection and response to mitigate risks associated with lightweight, adaptable malware like HOOKEDGE.

Related: Kuala Lumpur

Reporting based on The Hacker News. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.