Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HOOKEDGE is a lightweight Windows batch-script backdoor distributed through macro-enabled Microsoft Word documents using diplomatic-themed lures. It polls a staging webhook for arbitrary .cmd payloads, executes them, and returns command output to the webhook.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
It starts with an installer launcher that creates a scheduled task that runs every 30 minutes to execute the HOOKEDGE launcher with the backdoor as its argument.
HOOKEDGE... facilitate[s] remote command execution by fetching arbitrary .cmd payloads from a staging webhook [and] executing them.
The command retrieval and data exfiltration occur by launching a Microsoft Edge instance in headless mode or in a hidden window and making an HTTP request to the webhook.
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows batch-script backdoor used for remote command execution. It establishes persistence through a scheduled task, polls webhook[.]site endpoints for command payloads, executes retrieved .cmd files, exfiltrates output over HTTP via headless or hidden Microsoft Edge, and deletes temporary artifacts after execution. High-value victims may receive a second-stage payload with a five-minute beacon interval.
A lightweight Windows batch-script backdoor used for initial access. It uses webhook.site for command-and-control, payload staging, and data exfiltration; selected higher-value targets received a second-stage payload with a shorter beacon interval for more responsive operator tasking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.