APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
ID: bc3fe2d7-270c-5743-b472-832b252974fa
STIX ID: report--bc3fe2d7-270c-5743-b472-832b252974fa
Feed Name: The Hacker News
Recorded Future's Insikt Group observed a campaign attributed with moderate confidence to APT28 (tracked as BlueDelta) targeting government and diplomatic organizations in Romania, Spain, and Türkiye between September 2025 and April 2026. The attackers deployed a previously undocumented Windows batch backdoor called HOOKEDGE via macro-enabled Word documents that write files, create scheduled tasks, and fetch/execute .cmd payloads from webhook.site endpoints; operators used a two-stage architecture and webhook.site endpoints to manage C2 and conserve free-tier quotas. The report highlights code and tradecraft overlap with the earlier HEADLACE backdoor, describes iterative refinements to evade detection, and recommends blocking macros from internet-originated documents and monitoring for scheduled task abuse, headless Edge execution, and outbound connections to webhook services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
