HOOKEDGE is a lightweight Windows batch-script backdoor assessed as an evolutionary successor to the HEADLACE implant. It has been used in cyberespionage operations attributed with moderate confidence to BlueDelta, a Russian GRU-linked activity cluster also tracked as APT28, Fancy Bear, and Forest Blizzard. Observed campaigns targeted government, diplomatic, defense, and defense-manufacturing organizations in Romania, Spain, and Türkiye.
HOOKEDGE was delivered through spearphishing emails carrying macro-enabled Microsoft Word attachments, including diplomatic-themed lures. After a recipient enables macros, the infection chain deploys scripting components and creates a scheduled task for persistence. The backdoor polls staging infrastructure for command-script payloads, reconstructs and executes received commands, captures their output, and sends the results to separate collection infrastructure. It uses hidden or headless Microsoft Edge instances for tasking and output transmission, making its web traffic resemble ordinary browser activity. Operators used a public webhook service for command and control, payload staging, and exfiltration.
The malware removes installation, temporary, and downloaded artifacts after use. Observed variants altered macro obfuscation, browser execution mode, and beacon intervals, including delayed check-ins likely intended to reduce sandbox visibility. A higher-frequency second-stage deployment was used against selected victims, consistent with prioritization of higher-value intelligence targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlueDelta used macro-enabled Word documents with diplomatic-themed lures to deliver HOOKEDGE, a lightweight batch-script backdoor closely related to HEADLACE. HOOKEDGE abuses legitimate webhook services for C2, payload staging, and data exfiltration.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
“These components start a multi-stage installer, create a Windows scheduled task” and “A first-stage scheduled task could contact operators every 30 minutes.”
“the document’s AutoOpen routine writes batch, command, VBScript, HTML, and XHTML files into the user’s profile directory. These components start a multi-stage installer.”
“The group adjusted its methods during the observed period, including changing lures, obscuring VBA code.”
“a fake Word error message tries to make the suspicious behavior seem routine.”
“temporary files and download artifacts are deleted” and “later remove installation traces.”
T1140 — Deobfuscate/Decode Files or Information (Defense Evasion) est identifié dans la liste des TTPs.
“At set intervals, it opens Microsoft Edge to retrieve instructions from a staging endpoint” and “A second hidden Edge instance sends the collected output to a separate endpoint.”
Captures the resulting command output... Uses a second Microsoft Edge instance to submit the collected information through an HTTP POST request to a separate exfiltration webhook.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight batch-script backdoor delivered through macro-enabled Word documents. It uses legitimate webhook services for command-and-control, payload staging, and data exfiltration, blending malicious activity into legitimate web traffic.
A Windows espionage backdoor delivered through spearphishing macro-enabled Word documents. It establishes scheduled-task persistence, periodically retrieves commands through Microsoft Edge from webhook-based staging infrastructure, executes the commands, and exfiltrates their output through a separate endpoint while deleting temporary artifacts.
A Windows polling backdoor delivered through spearphishing macro-enabled Word documents. It establishes scheduled-task persistence, uses hidden Microsoft Edge instances to retrieve commands and exfiltrate command output via a public webhook service, and removes temporary installation and download artifacts.
A Windows polling backdoor delivered through macro-enabled Word documents. It establishes scheduled-task persistence, uses Microsoft Edge to retrieve commands from webhook.site, executes concatenated .cmd payloads, captures command output, and exfiltrates it through separate webhook endpoints. Higher-priority victims can receive a second instance with more frequent beaconing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.