APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye

APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and (TL-2026-2213), also tracked as HOOKEDGE Campaign, is a high-severity malware campaign, first published 2026-08-29. It is attributed to APT28 (Russia) with medium confidence, affects Microsoft Word (Microsoft 365 / Office), maps to 13 MITRE ATT&CK techniques (T1027.013, T1053.005, T1059.003), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-2213

Threat ID
TL-2026-2213
Also known as
HOOKEDGE Campaign, BlueDelta Diplomatic Espionage Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-29
Last reviewed
2026-08-29
Attribution
APT28
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, diplomatic, defense
Target regions
romania, spain, Türkiye, Europe
Detection rules
9
Indicators of compromise
20

Malware and tooling in APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and

Malware and tooling: HOOKEDGE, Headlace, SOURFACE

APT28 (Fancy Bear / Forest Blizzard), tracked by Recorded Future's Insikt Group as BlueDelta, ran a series of initial-access campaigns between late September 2025 and early April 2026 against government and diplomatic organizations in Romania, Spain, and Türkiye, delivering a lightweight Windows batch-script backdoor dubbed HOOKEDGE via macro-enabled Word documents.

How APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and works

Insikt Group assesses with moderate confidence that BlueDelta, which overlaps with APT28/Fancy Bear/Forest Blizzard and is attributed to Russia's GRU Main Directorate of the General Staff, ran an espionage campaign against European government and diplomatic targets from late September 2025 through early April 2026. The campaign opened with a macro-enabled Word document impersonating material from Spain's Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 8, 2025 meeting between Spanish and Moldovan officials, and later pivoted to generic 'Enable Content' lures with fake error dialogs targeting Romania, and eventually Türkiye by April 2026.

Opening the document's AutoOpen() macro drops six files into %userprofile%, including a GUID-named .bat/.vbs/.cmd chain (the HOOKEDGE payload, its launcher, and an installer) plus .htm/.xhtml staging files used to format exfiltrated output. The installer creates a scheduled task that re-executes the HOOKEDGE launcher every 30 minutes (later widened to 61 minutes, timed to outlast the roughly one-hour observation window of common sandboxes) and then self-deletes. HOOKEDGE itself is a polling-loop batch backdoor: it launches Microsoft Edge in headless or hidden-window mode to retrieve a `.cmd` payload from a dedicated webhook.site tasking endpoint, executes it locally via cmd.exe, and posts the results to a second, separate webhook.site endpoint for exfiltration, then cleans up temporary files. High-value targets receive a dedicated second-stage HOOKEDGE instance with its own webhook pair and a much tighter 5-minute beacon interval, enabling near-interactive tasking. Because webhook.site's free tier caps each endpoint at 100 requests, BlueDelta rotated endpoints frequently and lengthened beacon intervals to stretch the quota; operators accessed the webhook.site administration panel through NordVPN egress IPs to obscure themselves. Lure engineering included phishing-funnel tracking pixels (`docopened.jpg`, later `mailopened.jpg`) that beacon to webhook.site the moment a target opens the email or the document, giving operators delivery-success telemetry before any payload runs.

HOOKEDGE shares extensive code and tradecraft overlap with APT28's earlier HEADLACE backdoor (in use against diplomats since at least April 2023, including a March 2024 car-for-sale-themed campaign using an Audi Q7 decoy and DLL-sideloading via a trojanized calculator binary), including identical second-stage JavaScript variable names, structure, and base64 encoding schemes, near-identical GUID file-naming conventions, and the same reliance on abusing free web services (webhook.site, and previously Mocky) instead of adversary-owned infrastructure. Insikt Group assesses HOOKEDGE is a direct evolutionary successor to HEADLACE maintained by the same operators, reflecting BlueDelta's preference for lightweight, rapidly modifiable tooling over more complex implants.

MITRE ATT&CK techniques used in TL-2026-2213

Defense Evasion

T1027.013 Encrypted/Encoded File; T1070.004 File Deletion; T1497.003 Time Based Checks; T1564.003 Hidden Window

Persistence

T1053.005 Scheduled Task

Execution

T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication

Initial Access

T1566.001 Spearphishing Attachment

Exfiltration

T1567.004 Exfiltration Over Webhook

Resource Development

T1583.006 Web Services

Affected products and versions in APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and

  • Microsoft — Word (Microsoft 365 / Office)
    Vulnerable versions: any version with macros enabled for internet-sourced documents
    Fixed in: N/A - social-engineering delivery vector, not a software vulnerability
  • Microsoft — Windows (Task Scheduler, Edge)
    Vulnerable versions: all supported Windows versions with msedge.exe and Task Scheduler available
    Fixed in: N/A

Remediation for APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and

Immediate actions

  • Block or alert on outbound connections to webhook.site and similar generic webhook/request-bin services unless explicitly business-justified
  • Disable Office macros for documents originating from the internet, or restrict execution to signed VBA only
  • Hunt for scheduled tasks created in user-writable contexts that re-execute cmd.exe, wscript.exe, or a .bat/.vbs pair at 5-, 30-, or 61-minute intervals

Workarounds

  • Restrict or closely monitor outbound HTTP/HTTPS traffic to *.webhook.site at the network egress boundary

Longer-term hardening

  • Deploy EDR detections for msedge.exe launched with headless or hidden-window flags and no corresponding user activity
  • Enforce FIDO2/hardware-key MFA for externally facing services used by diplomatic and government staff to blunt post-compromise credential reuse
  • Build phishing-lure detection content for diplomatic-themed documents impersonating ministries or referencing recent bilateral meetings

Timeline of APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and

  • HEADLACE, HOOKEDGE's direct predecessor, is in use by APT28/BlueDelta against diplomatic targets as early as April 2023.
  • APT28 runs a HEADLACE campaign using a car-for-sale (Audi Q7) phishing decoy and DLL sideloading via a trojanized calculator binary to target diplomats.
  • Earlier May 2024 HEADLACE campaigns target European networks with credential-harvesting components using the same malware family.
  • The Hacker News publishes reporting on the HEADLACE car-sale-lure campaign, documenting APT28's webhook.site/Mocky-based C2 tradecraft.
  • Spanish and Moldovan officials hold a bilateral meeting that is subsequently referenced in the earliest HOOKEDGE lure document.
  • Earliest observed HOOKEDGE lure deployed, a macro-enabled Word document impersonating material from Spain's Ministry of the Presidency, Justice and Relations with the Cortes.
  • BlueDelta shifts to generic 'Enable Content' lures with fake error dialogs, expanding targeting to Romanian government organizations through December 2025.
  • Operators introduce a 'mailopened.jpg' webhook.site tracking canary alongside the existing 'docopened.jpg' canary to monitor the full phishing funnel.
  • HOOKEDGE variants targeting Türkiye are identified, marking the campaign's geographic expansion and the end of the documented late-September-2025-to-early-April-2026 activity window.
  • BlueDelta introduces minor VBA obfuscation changes to HOOKEDGE lure documents and removes the document-open tracking canary from later builds.
  • Recorded Future's Insikt Group publishes its BlueDelta/HOOKEDGE research; The Hacker News and other outlets report on the campaign the same day.

Sources cited for APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and

More in malware

Detection coverage for TL-2026-2213

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2213 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats