BlueDelta Targets Defense and Diplomacy with HOOKEDGE
ID: 2c5a1531-d266-5bf6-8247-e588ebbdef0c
STIX ID: report--2c5a1531-d266-5bf6-8247-e588ebbdef0c
Feed Name: Recorded Future Blog
Insikt Group attributes a series of September 2025–April 2026 initial-access campaigns to BlueDelta (linked to the GRU), which used macro-enabled Word lures to deploy a batch-script backdoor named HOOKEDGE against government and diplomatic targets in Romania, Spain, and Türkiye; HOOKEDGE polls staging webhooks, executes retrieved .cmd payloads via Microsoft Edge, and exfiltrates output to separate webhook endpoints hosted on webhook.site, with multiple refinements and second-stage payloads observed and numerous IOCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
