logo

APT28 Targeted European Entities Using Webhook-Based Macro Malware

ID: eed12a4f-a804-513d-8af7-c151b9c3bd6d

STIX ID: report--eed12a4f-a804-513d-8af7-c151b9c3bd6d

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-02-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Russia-linked APT28 conducted "Operation MacroMaze" (Sep 2025–Jan 2026), delivering spear-phishing Word documents that beacon to webhook.site via the INCLUDEPICTURE field and execute macros that run VBS/CMD/batch chains to render Base64 HTML in Microsoft Edge (headless or moved off-screen) to retrieve commands, execute them, and exfiltrate output back to webhook endpoints; the campaign emphasizes stealth using simple tooling, artifact cleanup, and widely used webhook services for payload delivery and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.