VMTech
Discuss a project

HOOKEDGE backdoor campaign targets European government organizations

HOOKEDGE backdoor campaign targets European government organizations

Recorded Future’s Insikt Group has identified campaigns against government and diplomatic organizations in Romania, Spain and Türkiye that deployed a previously undocumented Windows backdoor named HOOKEDGE. The activity ran from late September 2025 to early April 2026 and has been attributed with moderate confidence to APT28, the Russian state-sponsored group also known as Fancy Bear and Forest Blizzard. Recorded Future tracks the cluster as BlueDelta.

HOOKEDGE is a lightweight batch-script backdoor delivered through macro-enabled Microsoft Word documents using diplomatic-themed lures. Early samples impersonated Spanish government material before the operators shifted their social-engineering approach about a month later. Insikt Group said the malware is a direct evolutionary successor to HEADLACE, a modular Windows backdoor used against diplomats by APT28 since April 2023.

Macro lures establish a persistent execution chain

When a recipient opens a lure document, it asks them to select “Enable Content” to view it. The macro then writes six files into the user profile directory and starts the HOOKEDGE installer chain. An installer launcher creates a scheduled task configured to run the HOOKEDGE launcher every 30 minutes with the backdoor supplied as an argument.

The main installer subsequently removes itself, the installer launcher and the task-definition file. This deletion is intended to reduce the forensic footprint and complicate incident response. The document also contains a hidden image referencing a webhook.site URL, allowing the operators to receive an alert when a target opens the file.

Webhook infrastructure and Edge support command execution

Once active, HOOKEDGE polls a staging webhook for arbitrary .cmd payloads, executes them and returns the output through a webhook URL using an HTML file. It launches Microsoft Edge in headless mode or a hidden window to make HTTP requests. After transmission, the malware deletes temporary files and terminates processes whose window titles match its task identifier.

Recorded Future observed a second-stage HOOKEDGE payload against high-value targets with beaconing intervals as short as five minutes. The two-stage approach separates broad initial access from active collection and helps address webhook.site’s free-tier maximum of 100 requests for each unique endpoint. At a 30-minute interval, a single endpoint’s allowance could be consumed in roughly two to three days.

Detection should focus on the execution chain

The group continually refined the implant between September 2025 and April 2026, including adaptations intended to evade automated sandboxes and operate within reduced API limits. It also removed a document-open canary that had captured victim IP addresses, a change Insikt Group said may reduce network-based indicators of compromise.

For security teams, the practical implication is to block macro execution in internet-originated documents and build detection around scheduled-task abuse, hidden or headless Microsoft Edge activity, and outbound connections to webhook services.

#cybersecurity#apt28#malware#threatintel
Open analytics
On the site 0 views
min read 3 28.08.2026
Instagram

HOOKEDGE backdoor campaign targets European government organizations

Open the post on Instagram ↗