HackMyIP
← Back to News
2026-08-28 The Hacker News

APT28 HOOKEDGE Backdoor Hits European Diplomatic Organizations

APTMalwareThreat Intel

Cybersecurity researchers at Recorded Future's Insikt Group have uncovered a sustained cyber-espionage campaign attributed with moderate confidence to Russian state-sponsored threat actor APT28 (also known as Fancy Bear, Forest Blizzard, and tracked internally as BlueDelta). Active between late September 2025 and early April 2026, the operation targeted government and diplomatic entities in Romania, Spain, and Türkiye, deploying a previously undocumented Windows batch backdoor dubbed HOOKEDGE.

HOOKEDGE is described as a direct evolutionary successor to APT28's HEADLACE backdoor, which has been used against diplomats since April 2023. Researchers identified significant overlap in core architecture and tradecraft, including the abuse of webhook[.]site services for command-and-control communications, payload staging, and data exfiltration. This approach allows malicious traffic to blend with legitimate network activity, eliminating the need for dedicated attacker infrastructure. The implant has undergone continuous refinement, likely to evade automated sandbox environments and adapt to reductions in webhook[.]site's free-tier API limits. Organizations can assess their exposure to such covert C2 channels by running a DNS leak test to identify unexpected outbound queries, or by using a port scanner to flag suspicious listening services on endpoints.

The primary delivery vehicle is a macro-enabled Microsoft Word document bearing diplomatic-themed lures. Early iterations impersonated official Spanish government material before pivoting to broader social engineering themes roughly one month later. When a target clicks "Enable Content," the embedded macro writes six files to the %userprofile% directory and initiates the HOOKEDGE installer chain. An installer launcher creates a scheduled task running every 30 minutes to execute the HOOKEDGE launcher with the backdoor as its argument, after which the installer and task definition file are deleted to minimize forensic footprint and complicate incident response. A hidden image embedded in the lure document also pings a webhook[.]site URL the moment the file is opened, giving operators near-real-time confirmation of successful targeting.

The HOOKEDGE backdoor itself is a lightweight Windows batch script that enters a continuous polling loop. It fetches arbitrary .cmd payloads from a staging webhook, executes them, and returns output via an HTML file to a webhook URL, using a headless Microsoft Edge instance for retrieval and exfiltration. Security teams should run a privacy checkup across executive and diplomatic endpoints to validate that macro execution policies, scheduled task auditing, and outbound traffic monitoring are properly configured to detect this class of implant.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →