logo

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

ID: 2c5a1531-d266-5bf6-8247-e588ebbdef0c

STIX ID: report--2c5a1531-d266-5bf6-8247-e588ebbdef0c

Feed Name: Recorded Future Blog

Threat Score
88/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

...
...

Insikt Group attributes a series of September 2025–April 2026 initial-access campaigns to BlueDelta (linked to the GRU), which used macro-enabled Word lures to deploy a batch-script backdoor named HOOKEDGE against government and diplomatic targets in Romania, Spain, and Türkiye; HOOKEDGE polls staging webhooks, executes retrieved .cmd payloads via Microsoft Edge, and exfiltrates output to separate webhook endpoints hosted on webhook.site, with multiple refinements and second-stage payloads observed and numerous IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.