Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

APT28-Linked HOOKEDGE Backdoor: A Sophisticated Threat to European Governments and Diplomatic Organizations


A sophisticated backdoor linked to APT28 has been found to be targeting European governments and diplomatic organizations. The HOOKEDGE backdoor, a lightweight Windows batch script, has been distributed via macro-enabled Microsoft Word documents and has been linked to APT28. This backdoor poses a significant threat to the security of these organizations and highlights the evolving nature of state-sponsored hacking groups.

  • APT28-linked HOOKEDGE backdoor distributed via macro-enabled Microsoft Word documents.
  • Targeted at government and diplomatic organizations in Romania, Spain, and Türkiye between September 2025 and April 2026.
  • Attributed to a Russian state-sponsored hacking group with similarities to a modular Windows backdoor used by APT28 since April 2023.
  • Features a polling loop to facilitate remote command execution and a two-stage payload architecture.
  • Includes features to reduce network-based indicators of compromise.
  • Organizations recommended to block macro execution, detect scheduled task abuse, headless Edge execution, and outbound connections to webhook services.



  • The threat landscape of cybersecurity has witnessed numerous high-profile attacks in recent times, with the latest one being the APT28-linked HOOKEDGE backdoor. This backdoor, which is a lightweight Windows batch script, has been found to be distributed via macro-enabled Microsoft Word documents bearing diplomatic-themed lures. According to the latest reports, the HOOKEDGE backdoor has been targeted at government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.

    The deployment of this backdoor has been attributed with moderate confidence to a Russian state-sponsored hacking group known as APT28, also famously referred to as Fancy Bear and Forest Blizzard. This attribution is based on significant code and tradecraft overlap between HOOKEDGE and a modular Windows backdoor previously used by APT28 in attacks targeting diplomats since April 2023.

    One of the most striking features of HOOKEDGE is its similarity to a modular Windows backdoor previously used by APT28 in attacks targeting diplomats since April 2023. This includes similarities in core architecture and the abuse of webhook[.]site services for command-and-control (C2), payload staging, and data exfiltration. This allows malicious activity to blend in with regular network traffic and obviates the need for setting up dedicated infrastructure.

    The primary delivery vehicle for HOOKEDGE is a macro-enabled Microsoft Word document that, when opened, prompts the target to click "Enable Content" to display the contents. This prompts the macro routing to write six files to the "%userprofile%" directory and launch the HOOKEDGE installer chain. The main installer then deletes itself, along with the installer launcher, and the task definition file, from the directory in an attempt to cover up traces of the malicious activity and complicate incident response efforts.

    In addition to its primary delivery mechanism, HOOKEDGE also includes several features that enable it to operate seamlessly in the background. This includes a polling loop to facilitate remote command execution by fetching arbitrary .cmd payloads from a staging webhook, executing them, and sending the resulting output back to the webhook URL using an HTML file. The command retrieval and data exfiltration occur by launching a Microsoft Edge instance in headless mode or in a hidden window and making an HTTP request to the webhook.

    The deployment of HOOKEDGE has been observed to include a second-stage payload against high-value targets with a beaconing interval as little as five minutes. This allows the threat actors to have more operational control over tasking and interactive post-compromise activity. The two-stage architecture also helps to mitigate one of BlueDelta's infrastructure constraints, as webhook[.]site's free tier imposes a maximum of 100 requests per unique endpoint, meaning a 30-minute beaconing interval would exhaust a given endpoint's request allocation within approximately two to three days.

    The BlueDelta group is believed to have continually tweaked the modus operandi to better suit its operational requirements, going as far as to remove the document-open canary that captured the victim IP addresses when the document was opened. This is suspected to be an attempt to reduce network-based indicators of compromise.

    To counter the threat posed by HOOKEDGE, organizations are recommended to prioritize blocking macro execution from internet-originated documents, and implement detection coverage for scheduled task abuse, headless Microsoft Edge execution, and outbound connections to webhook services.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/APT28-Linked-HOOKEDGE-Backdoor-A-Sophisticated-Threat-to-European-Governments-and-Diplomatic-Organizations-ehn.shtml

  • https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html

  • https://securereading.com/apt28-hookedge-backdoor-european-government-targets/


  • Published: Sat Aug 29 19:24:21 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us