Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
N-able Patches Critical RCE Vulnerability in N-central Platform
September 7, 2026
New Chrome Extension Steals Login Sessions, Creates Backdoors
September 7, 2026
Best Business Antivirus and Endpoint Protection Software for 2024
September 7, 2026
Home/Threats/APT28 Uses New HOOKEDGE Backdoor to Spy on European Organizations
Threats

APT28 Uses New HOOKEDGE Backdoor to Spy on European Organizations

Key Takeaways Russian state-sponsored group APT28 (BlueDelta, Fancy Bear, Forest Blizzard) is deploying a new Windows backdoor, HOOKEDGE, in espionage campaigns. Targets include diplomatic,...

Jennifer sherman
Jennifer sherman
September 7, 2026 4 Min Read
3 0

Key Takeaways

  • Russian state-sponsored group APT28 (BlueDelta, Fancy Bear, Forest Blizzard) is deploying a new Windows backdoor, HOOKEDGE, in espionage campaigns.
  • Targets include diplomatic, governmental, and defense organizations in European countries such as Romania, Spain, and Turkey.
  • The attack chain leverages spearphishing emails with malicious Microsoft Word documents that execute macros to install the multi-stage backdoor.
  • HOOKEDGE uses legitimate Windows features and a public webhook service to blend in with normal network traffic, making detection challenging.
  • The backdoor is an evolution of APT28’s previous HEADLACE malware, indicating continuous development in their toolset.

Russian APT28 Deploys Stealthy HOOKEDGE Backdoor in European Espionage Campaign

A new Windows backdoor, dubbed HOOKEDGE, is being actively utilized by the Russian state-sponsored advanced persistent threat (APT) group APT28 in sophisticated espionage operations targeting critical European entities. The campaign has primarily focused on diplomatic, government, and defense organizations across Romania, Spain, and Turkey, employing seemingly innocuous Microsoft Word attachments as the initial compromise vector.

Table Of Content

  • Key Takeaways
  • Russian APT28 Deploys Stealthy HOOKEDGE Backdoor in European Espionage Campaign
  • The HOOKEDGE Attack Chain
  • Stealth and Evasion Tactics
  • What You Should Do

The malicious activity, detailed in a recent report by PolySwarm said in a report shared with Cyber Security News (CSN), highlights APT28’s preference for stealthy, low-cost access over more overt, resource-intensive methods. This approach allows the group to maintain persistent access and exfiltrate sensitive information with a reduced risk of immediate detection.

The HOOKEDGE Attack Chain

The infection begins with spearphishing emails containing macro-enabled Microsoft Word documents. Victims are tricked into enabling content, which triggers hidden scripts. Simultaneously, a fabricated Word error message appears, attempting to legitimize the suspicious behavior and lull the user into a false sense of security. This single user action establishes a persistent channel for remote espionage.

Once activated, the document’s AutoOpen routine writes a series of batch, command, VBScript, HTML, and XHTML files to the user’s profile directory. These components initiate a multi-stage installer, set up a Windows scheduled task for persistence, and then meticulously remove the installation traces. This method of using weaponized Office documents as an initial entry point is a recurring tactic for APT28, demonstrating the continued effectiveness of exploiting trusted productivity files.

Stealth and Evasion Tactics

PolySwarm’s analysis, which incorporates research from Recorded Future, links this activity to BlueDelta (a moniker for APT28, also known as Fancy Bear and Forest Blizzard) with moderate confidence. The researchers describe HOOKEDGE as a refined version of the group’s earlier HEADLACE backdoor.

HOOKEDGE operates as a polling backdoor, periodically initiating hidden instances of Microsoft Edge. These browser instances are used to retrieve commands from a staging endpoint, assemble them into a command file, execute it, and capture the results. A second hidden Edge instance then transmits the collected output to a separate exfiltration endpoint. Crucially, all temporary files and download artifacts are deleted after each communication cycle.

This segmented approach for command and control (C2) and data exfiltration enhances operational security for the attackers. By separating the tasking and data theft channels, a compromise of one service does not necessarily expose the entire operation. Furthermore, utilizing a public webhook service and mimicking legitimate Microsoft Edge HTTPS traffic makes the backdoor’s communications difficult to distinguish from normal web browsing, posing a significant challenge for traditional security tools that rely solely on domain reputation.

Researchers observed a tiered approach to victim interaction. Initial compromises established a scheduled task that contacted operators every 30 minutes. For high-value targets, a second HOOKEDGE instance was deployed, beaconing as frequently as every five minutes. This accelerated communication allows operators to rapidly collect intelligence once a victim’s strategic importance is confirmed.

APT28 has continuously adapted its tactics throughout this campaign. Observed changes include evolving lures, obfuscating VBA code, transitioning from headless Edge execution to hidden windows, and varying beacon intervals. A later first-stage variant incorporated a 61-minute delay between contacts, likely designed to conserve webhook requests and bypass automated analysis systems that typically monitor files for shorter durations.

What You Should Do

  • Exercise Extreme Caution with Attachments: Treat all unsolicited macro-enabled documents, especially those with diplomatic or administrative themes, as high-risk. Disable or strictly control macros from files originating outside your organization’s trusted network.
  • Monitor for Suspicious Scheduled Tasks: Regularly review newly created or modified scheduled tasks on endpoints. Look for tasks that may be designed for persistence or to execute unusual scripts.
  • Correlate Browser Activity with System Events: Implement advanced monitoring to correlate unusual Microsoft Edge browser launches (especially hidden instances) with unexpected command shell executions or script file creations.
  • Implement Behavioral Detection: Focus detection efforts on behavioral patterns rather than just static indicators. Look for sequences like Word launching scripts, scripts registering scheduled tasks, and Edge posting data to unusual webhook paths.
  • Preserve Logs for Forensics: In the event of a suspected compromise, prioritize preserving endpoint and proxy logs. HOOKEDGE’s self-cleaning mechanisms mean temporary artifacts that could explain the intrusion may be deleted if not captured promptly.
  • Review Indicators of Compromise (IoCs): Incorporate the following IoCs into your security monitoring and threat intelligence platforms:
    • Domain: webhook[.]site (Service abused for command retrieval, payload staging, and data exfiltration)
    • File name: mailopened.jpg (Email-open telemetry canary)
    • File name: docopened.jpg (Document-open telemetry canary)
    • File name: doc.jpg (Later-stage execution telemetry canary)
    • SHA-256: 206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991
    • SHA-256: 231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1
    • SHA-256: 58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e
    • SHA-256: 5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a
    • SHA-256: 87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3
    • SHA-256: 9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc
    • SHA-256: aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360
    • SHA-256: b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4
    • SHA-256: c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44
    • SHA-256: df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6
    • SHA-256: ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1
    • SHA-256: f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca

    Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackHackerMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical PaperCut Flaws Let Attackers Execute Code, Exploit Underway

Next Post

Top 10 Managed Firewall Services for 2026

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Software Vulnerabilities Surge 500% Monthly
September 7, 2026
Top 10 Managed Firewall Services for 2026
September 7, 2026
APT28 Uses New HOOKEDGE Backdoor to Spy on European Organizations
September 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us