Russian state-linked threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has used a lightweight Windows backdoor named HOOKEDGE in cyberespionage operations against European diplomatic, government, and defense-sector organizations.
Researchers linked the activity to targets in Romania, Spain, and Turkey, with campaign activity observed from late September 2025 through early April 2026 and newer variants emerging during June and July 2026.
According to Polyswarm, BlueDelta delivered HOOKEDGE through spearphishing attachments containing macro-enabled Microsoft Word documents.
Russian APT28-Linked Hackers Deploy HOOKEDGE Backdoor
Early lures used diplomatic themes, including a file impersonating material from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.
Later campaigns shifted to generic documents containing junk text or prompts that asked recipients to select “Enable Content.” When a victim enables macros, the document displays a fake Microsoft Word error message while its AutoOpen() routine begins a multi-stage infection process in the background.
The macro writes batch, command, VBScript, HTML, and XHTML files into the user profile directory. These components ensure persistence via a Windows Scheduled Task that launches the HOOKEDGE payload at configured intervals.
Installation scripts subsequently remove themselves and associated artifacts, limiting evidence available to incident responders. HOOKEDGE operates as a polling backdoor, relying on Microsoft Edge rather than on a dedicated malware networking component.
During each execution cycle, the backdoor clears download artifacts, launches msedge.exe, and contacts attacker-controlled endpoints created through webhook[.]site.
The malware retrieves staged content, combines it into a .cmd payload, executes the command, captures its output, and embeds the results in an HTML file.
A second Edge instance then submits that data to a separate webhook endpoint via an HTTP POST request before deleting the temporary files.
Using Microsoft Edge and a legitimate webhook platform helps the operation blend into ordinary HTTPS browser traffic. Earlier versions ran Edge in headless mode, while later variants used hidden browser windows.
BlueDelta also reportedly administered observed webhook endpoints through NordVPN IP addresses, adding another layer of operational concealment.
Polyswarm found that BlueDelta used HOOKEDGE to selectively intensify surveillance of compromised organizations. A first-stage implant could beacon every 30 minutes, while secondary HOOKEDGE instances deployed against higher-value victims communicated as frequently as every five minutes.
This tiered approach likely allows operators to identify successful and strategically important compromises before committing additional infrastructure and operational effort. It also helps avoid webhook[.]site free-tier request limits, which cap the number of requests at 100.
A later first-stage variant used a 61-minute beacon interval. The timing may reduce endpoint consumption while potentially bypassing automated sandbox systems that typically monitor suspicious programs for about 1 hour.
HOOKEDGE shares substantial code and operational overlap with BlueDelta’s previously documented HEADLACE backdoor. Both use Windows batch scripting, browser-mediated command-and-control, legitimate internet services, hidden execution, and lightweight payload-delivery mechanisms.
Recorded Future assessed with moderate confidence that HOOKEDGE is a direct evolution of HEADLACE and that BlueDelta conducted the campaign.
The targeting pattern focused on European government, diplomatic, and defense-related entities aligns with longstanding Russian intelligence-collection priorities.
The activity shows how state-backed operators can achieve persistent espionage access without deploying technically complex malware.
Defenders should monitor macro-enabled attachments, suspicious scheduled tasks, unusual Edge child processes, browser-launched command scripts, and connections to newly created webhook services.
IOCs
| SHA-256 Hash |
|---|
206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991 |
231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1 |
58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e |
5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a |
87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3 |
9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc |
aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360 |
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4 |
c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44 |
df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6 |
ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1 |
f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca |
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN