Russian GRU-linked espionage group BlueDelta—also tracked as APT28, Fancy Bear, and Forest Blizzard—targeted government, diplomatic, and defense-manufacturing organizations in Romania, Spain, and Türkiye from late September 2025 through early April 2026. The group used macro-enabled Microsoft Word lures, including documents impersonating Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, to gain initial access and deploy the Windows batch-script backdoor HOOKEDGE.
HOOKEDGE substantially overlaps with BlueDelta’s earlier HEADLACE implant and uses webhook[.]site for command-and-control, payload staging, and data exfiltration. Operators refined lure themes, execution techniques, and beaconing cadence during the activity, using more frequent second-stage callbacks for higher-value targets; defenders should block macros in internet-originated documents and monitor for scheduled-task abuse, headless Microsoft Edge processes, and outbound webhook-service connections.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Recorded Future observed additional HOOKEDGE variants in June and July 2026 after the previously documented campaign period. July samples removed the document-open canary, reflecting a subsequent change to BlueDelta's lure-tracking mechanism.
The earliest identified lure was observed on September 26, 2025. It impersonated a September 15 meeting agenda from Spain's Ministry of the Presidency, Justice and Relations with the Cortes.
Across the September 2025 to April 2026 campaign period, BlueDelta changed lures, execution methods, and beaconing intervals, including a faster-beaconing second-stage payload for targets assessed as higher intelligence value. HOOKEDGE used webhook[.]site for command and control, payload staging, and data exfiltration.
From late September 2025 through early April 2026, the GRU-linked BlueDelta group used macro-enabled Word documents to deploy the HOOKEDGE batch-script backdoor against government, diplomatic, and defense-manufacturing organizations in Romania, Spain, and Türkiye.
BlueDelta previously used its HEADLACE backdoor in initial-access campaigns targeting organizations across Europe.
Technical reporting disclosed HOOKEDGE canary webhook paths used to record email and document opens, along with payload artifact names, webhook endpoints, and sample hashes associated with the campaign. The reporting also identified a 61-minute first-stage check-in configuration intended to evade one-hour automated analysis windows.
Recorded Future assessed with moderate confidence that the GRU-linked BlueDelta group overlaps with APT28, also known as Fancy Bear and Forest Blizzard. It also assessed HOOKEDGE as an evolutionary successor to BlueDelta's earlier HEADLACE backdoor maintained by the same operators.
Technical analysis found that HOOKEDGE's installer creates a scheduled task that runs every 30 minutes. The backdoor retrieves command-script payloads and returns output through HTTP requests made by hidden or headless Microsoft Edge, then deletes temporary files and terminates processes associated with its task identifier.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 50 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcerecordedfuture.com
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.