Russian state-linked operators used the HOOKEDGE Windows backdoor in spearphishing campaigns against diplomatic, government, and defense-related organizations in Romania, Spain, and Turkey. Malicious emails carried macro-enabled Microsoft Word attachments whose hidden scripts deployed a multistage installer after recipients enabled content; the malware then created scheduled tasks for persistence.
HOOKEDGE launches concealed Microsoft Edge instances to poll attacker staging infrastructure, including webhook.site, retrieve commands, and exfiltrate collected results over HTTPS through separate hidden browser sessions. Recorded Future attributed the activity to the GRU-associated BlueDelta/APT28 group with moderate confidence, assessing HOOKEDGE as an evolution of HEADLACE; operators also varied lures, VBA obfuscation, execution methods, and beacon intervals—including a 61-minute delay—to complicate detection and sandbox analysis while removing temporary artifacts.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
A threat-research report published webhook.site command-and-control and exfiltration URL paths, 26 SHA-256 hashes, and detection queries for identifying HOOKEDGE activity attributed to BlueDelta/APT28.
Recorded Future linked the HOOKEDGE activity to the GRU-associated BlueDelta group, also tracked as APT28, Fancy Bear, and Forest Blizzard, with moderate confidence. Researchers assessed HOOKEDGE as an evolution of the earlier HEADLACE backdoor and documented changes to lures, VBA obfuscation, Edge execution, and beacon intervals.
Russian operators used the HOOKEDGE Windows backdoor in spearphishing-led espionage operations against diplomatic, government, and defense-related organizations in Romania, Spain, and Turkey. The campaign established scheduled-task persistence, used hidden Microsoft Edge instances and webhook.site for command retrieval and exfiltration, and removed temporary artifacts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 49 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.