HOOKEDGE Malware Spies on European Defense and Diplomacy
Key Takeaways A Russian-linked threat actor, BlueDelta (also known as APT28 or Fancy Bear), is deploying a new backdoor, HOOKEDGE. The malware targets defense contractors, government entities, and...
Key Takeaways
- A Russian-linked threat actor, BlueDelta (also known as APT28 or Fancy Bear), is deploying a new backdoor, HOOKEDGE.
- The malware targets defense contractors, government entities, and diplomatic organizations across Romania, Spain, and Türkiye.
- HOOKEDGE infiltrates systems via weaponized Microsoft Word documents that leverage macros.
- The threat actor uses public webhook services and hidden Microsoft Edge browser sessions to evade detection.
- Defenders should disable macros, implement phishing-resistant MFA, and monitor for unusual browser activity and scheduled tasks.
A sophisticated new backdoor, dubbed HOOKEDGE, is being actively deployed by Russian-affiliated hackers against high-value targets in Europe. This campaign specifically focuses on defense manufacturers, governmental bodies, and diplomatic missions in Romania, Spain, and Türkiye, utilizing a novel approach to stealthily exfiltrate sensitive information.
Table Of Content
The attack vector relies on seemingly benign Microsoft Word documents. These files, crafted to appear as routine or official communications, serve as the initial infection point in a multi-stage espionage operation.
Victims are lured into enabling macros embedded within these documents. This seemingly innocuous action triggers a complex sequence of scripts that ultimately install the HOOKEDGE backdoor, establish persistence through Windows Task Scheduler, and create a covert channel for the attackers to harvest data.
Analysts at Recorded Future’s Insikt Group have attributed this activity to BlueDelta, a prominent Russian state-sponsored threat group also recognized by various aliases such as APT28, Fancy Bear, and Forest Blizzard. Based on their analysis, Recorded Future assesses with moderate confidence that these operations are in direct support of Russian intelligence collection efforts, as detailed in a comprehensive report from Recorded Future.
Recorded Future said in a report that the significance of this campaign lies in its ability to leverage commonplace, trusted services and software, making the backdoor remarkably difficult to detect. This strategy allows the malware to blend seamlessly with legitimate network traffic, circumventing traditional security measures.
HOOKEDGE routes its command and control (C2) communications through public webhook services and hidden instances of Microsoft Edge. This innovative technique minimizes suspicious network indicators that would typically flag conventional attacker-controlled infrastructure.
Russian Hackers Employing New HOOKEDGE Malware
BlueDelta initiates its intrusions by distributing macro-enabled Word documents, most likely delivered via highly targeted spearphishing emails. Early iterations of these malicious documents mimicked official communications from Spain’s Ministry of the Presidency, Justice, and Relations with the Cortes. Subsequent versions adopted more generic prompts, simply urging recipients to enable content, a tactic consistent with weaponized Office document campaigns previously associated with APT28.
Upon macro execution, the malicious document writes several files to the user’s profile directory and launches an installer. This process then establishes a scheduled task for persistence and attempts to erase much of its installation footprint. Security teams should be vigilant for any unfamiliar scheduled tasks initiating scripts from user-writable folders, as Windows scheduled task abuse is a common method for achieving persistent access.
HOOKEDGE operates as a lightweight Windows batch-script backdoor. During each check-in, it queries a staging endpoint for new commands, reconstructs the command into a file, executes it, and then transmits the results to a separate endpoint. This entire communication process leverages obscured Edge browser sessions, effectively camouflaging malicious requests as standard web browsing activity. For particularly valuable targets, the operators deploy a secondary HOOKEDGE instance configured to check in every five minutes, significantly increasing the pace of data collection, compared to the default 30-minute interval. This suggests a strategic triage model, where initial broad access is followed by accelerated intelligence gathering from high-priority victims. This methodology is also consistent with the group’s established practice of employing cloud service command channels to conceal their activities within legitimate network traffic.
HOOKEDGE represents an evolution from BlueDelta’s previous backdoor, HEADLACE. Both malware variants share common characteristics, including their reliance on batch scripting and browser-based communication mechanisms, as noted in a Recorded Future report.
Defenders Should Watch the Edges
The threat group continuously refined the HOOKEDGE malware between September 2025 and April 2026, implementing changes to its lures, browser settings, and check-in intervals. A notable modification involved extending the initial check-in interval to 61 minutes. This delay was likely engineered to bypass automated analysis systems, which often observe suspicious files for approximately one hour, as detailed in the <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/d305fca0-ddb2-44a3-9fa1-8947a28da8e5/Russian-Hackers-Use-New-HOOKEDGE-Malware-to-Spy-on-European-Defense-and-Diplomatic-Targets.pdf?AWSAccessKeyId=ASIA2F3EMEYEQAT777NU&Signature=rICHUXYMK0v9ym2Fi613k6hkKNU%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEIb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCJsAWEo0rVAzZ6YQTwLtElQ%2FSzxNrXJaxaVW5%2BEzslTwIgQLNn687z0a1F7j2e4ioB0KJdqYbLNfGHA7YKwARd5Lkq8wQITxABGgw2OTk3NTMzMDk3MDUiDJSM5WTbUqbACANVpSrQBO0C1snqMmC5iN8W842c2vIflwXLdlQUNklFr8ZZzPCzAdIl0yQquBm%2FXoceFQoir2CmEUJ7LxKdLaHJvIC8jNuPFhTV%2Bgxhc%2FpTyEuV15H9CwJG3zGtxgwQGFNXiz0fo8A%2Fms7rRsaVZEO3PQ5ir2jykscGr9X151iLiC7%2BYsnPIKdGgeca8i%2FFD12FKnxHZvtaFxZQrvt%2Fxsx83t6px0SYf46LMqEHvV%2BeDJQXv87kXppigpEt%2FT24NFKuz46cNsSGsIiK0R0IgiPUmkhsAGcogpdbc7xtsUuaES2OZidsSAKNdcwKwLIfPAdgMqRnTnNvr%2FK89%2BShnTxM1mWw9%2Bd9dQ%2B7kBNoqNjtiJlFyvDhf44N%2B6VI%2BdCG%2B33cGfI%2Fo1NPhZXcoipYEdjuDVf7CPcpXzrcgPgbZPLbxnE48lQqlefNtJ0MQRwudV94z3EpnnW9i3FJL7kjiGF4vybxV87RNxgOTIfxv0VP%2FvOWA%2FFxc9G3w2eAj27oP0xa2I79FZjYSOlN7LKnVDjqTYT%
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.