Russian APT28-Linked Hackers Deploy HOOKEDGE Backdoor in European Espionage Attacks

Russian state-linked threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has used a lightweight Windows backdoor named HOOKEDGE in cyberespionage operations against European diplomatic, government, and defense-sector organizations.

Researchers linked the activity to targets in Romania, Spain, and Turkey, with campaign activity observed from late September 2025 through early April 2026 and newer variants emerging during June and July 2026.

According to Polyswarm, BlueDelta delivered HOOKEDGE through spearphishing attachments containing macro-enabled Microsoft Word documents.

Russian APT28-Linked Hackers Deploy HOOKEDGE Backdoor

Early lures used diplomatic themes, including a file impersonating material from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.

Later campaigns shifted to generic documents containing junk text or prompts that asked recipients to select “Enable Content.” When a victim enables macros, the document displays a fake Microsoft Word error message while its AutoOpen() routine begins a multi-stage infection process in the background.

The macro writes batch, command, VBScript, HTML, and XHTML files into the user profile directory. These components ensure persistence via a Windows Scheduled Task that launches the HOOKEDGE payload at configured intervals.

Installation scripts subsequently remove themselves and associated artifacts, limiting evidence available to incident responders. HOOKEDGE operates as a polling backdoor, relying on Microsoft Edge rather than on a dedicated malware networking component.

During each execution cycle, the backdoor clears download artifacts, launches msedge.exe, and contacts attacker-controlled endpoints created through webhook[.]site.

The malware retrieves staged content, combines it into a .cmd payload, executes the command, captures its output, and embeds the results in an HTML file.

A second Edge instance then submits that data to a separate webhook endpoint via an HTTP POST request before deleting the temporary files.

Using Microsoft Edge and a legitimate webhook platform helps the operation blend into ordinary HTTPS browser traffic. Earlier versions ran Edge in headless mode, while later variants used hidden browser windows.

BlueDelta also reportedly administered observed webhook endpoints through NordVPN IP addresses, adding another layer of operational concealment.

Polyswarm found that BlueDelta used HOOKEDGE to selectively intensify surveillance of compromised organizations. A first-stage implant could beacon every 30 minutes, while secondary HOOKEDGE instances deployed against higher-value victims communicated as frequently as every five minutes.

This tiered approach likely allows operators to identify successful and strategically important compromises before committing additional infrastructure and operational effort. It also helps avoid webhook[.]site free-tier request limits, which cap the number of requests at 100.

A later first-stage variant used a 61-minute beacon interval. The timing may reduce endpoint consumption while potentially bypassing automated sandbox systems that typically monitor suspicious programs for about 1 hour.

HOOKEDGE shares substantial code and operational overlap with BlueDelta’s previously documented HEADLACE backdoor. Both use Windows batch scripting, browser-mediated command-and-control, legitimate internet services, hidden execution, and lightweight payload-delivery mechanisms.

Recorded Future assessed with moderate confidence that HOOKEDGE is a direct evolution of HEADLACE and that BlueDelta conducted the campaign.

The targeting pattern focused on European government, diplomatic, and defense-related entities aligns with longstanding Russian intelligence-collection priorities.

The activity shows how state-backed operators can achieve persistent espionage access without deploying technically complex malware.

Defenders should monitor macro-enabled attachments, suspicious scheduled tasks, unusual Edge child processes, browser-launched command scripts, and connections to newly created webhook services.

IOCs

SHA-256 Hash
206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991
231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1
58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e
5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a
87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3
9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc
aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4
c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44
df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6
ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1
f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories