APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye
APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and (TL-2026-2213), also tracked as HOOKEDGE Campaign, is a high-severity malware campaign, first published 2026-08-29. It is attributed to APT28 (Russia) with medium confidence, affects Microsoft Word (Microsoft 365 / Office), maps to 13 MITRE ATT&CK techniques (T1027.013, T1053.005, T1059.003), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-2213
- Threat ID
- TL-2026-2213
- Also known as
- HOOKEDGE Campaign, BlueDelta Diplomatic Espionage Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-29
- Last reviewed
- 2026-08-29
- Attribution
- APT28
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomatic, defense
- Target regions
- romania, spain, Türkiye, Europe
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and
Malware and tooling: HOOKEDGE, Headlace, SOURFACE
APT28 (Fancy Bear / Forest Blizzard), tracked by Recorded Future's Insikt Group as BlueDelta, ran a series of initial-access campaigns between late September 2025 and early April 2026 against government and diplomatic organizations in Romania, Spain, and Türkiye, delivering a lightweight Windows batch-script backdoor dubbed HOOKEDGE via macro-enabled Word documents.
How APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and works
Insikt Group assesses with moderate confidence that BlueDelta, which overlaps with APT28/Fancy Bear/Forest Blizzard and is attributed to Russia's GRU Main Directorate of the General Staff, ran an espionage campaign against European government and diplomatic targets from late September 2025 through early April 2026. The campaign opened with a macro-enabled Word document impersonating material from Spain's Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 8, 2025 meeting between Spanish and Moldovan officials, and later pivoted to generic 'Enable Content' lures with fake error dialogs targeting Romania, and eventually Türkiye by April 2026.
Opening the document's AutoOpen() macro drops six files into %userprofile%, including a GUID-named .bat/.vbs/.cmd chain (the HOOKEDGE payload, its launcher, and an installer) plus .htm/.xhtml staging files used to format exfiltrated output. The installer creates a scheduled task that re-executes the HOOKEDGE launcher every 30 minutes (later widened to 61 minutes, timed to outlast the roughly one-hour observation window of common sandboxes) and then self-deletes. HOOKEDGE itself is a polling-loop batch backdoor: it launches Microsoft Edge in headless or hidden-window mode to retrieve a `.cmd` payload from a dedicated webhook.site tasking endpoint, executes it locally via cmd.exe, and posts the results to a second, separate webhook.site endpoint for exfiltration, then cleans up temporary files. High-value targets receive a dedicated second-stage HOOKEDGE instance with its own webhook pair and a much tighter 5-minute beacon interval, enabling near-interactive tasking. Because webhook.site's free tier caps each endpoint at 100 requests, BlueDelta rotated endpoints frequently and lengthened beacon intervals to stretch the quota; operators accessed the webhook.site administration panel through NordVPN egress IPs to obscure themselves. Lure engineering included phishing-funnel tracking pixels (`docopened.jpg`, later `mailopened.jpg`) that beacon to webhook.site the moment a target opens the email or the document, giving operators delivery-success telemetry before any payload runs.
HOOKEDGE shares extensive code and tradecraft overlap with APT28's earlier HEADLACE backdoor (in use against diplomats since at least April 2023, including a March 2024 car-for-sale-themed campaign using an Audi Q7 decoy and DLL-sideloading via a trojanized calculator binary), including identical second-stage JavaScript variable names, structure, and base64 encoding schemes, near-identical GUID file-naming conventions, and the same reliance on abusing free web services (webhook.site, and previously Mocky) instead of adversary-owned infrastructure. Insikt Group assesses HOOKEDGE is a direct evolutionary successor to HEADLACE maintained by the same operators, reflecting BlueDelta's preference for lightweight, rapidly modifiable tooling over more complex implants.
MITRE ATT&CK techniques used in TL-2026-2213
Defense Evasion
T1027.013 Encrypted/Encoded File; T1070.004 File Deletion; T1497.003 Time Based Checks; T1564.003 Hidden Window
Persistence
Execution
T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication
Initial Access
T1566.001 Spearphishing Attachment
Exfiltration
T1567.004 Exfiltration Over Webhook
Resource Development
Affected products and versions in APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and
- Microsoft — Word (Microsoft 365 / Office)
Vulnerable versions: any version with macros enabled for internet-sourced documents
Fixed in: N/A - social-engineering delivery vector, not a software vulnerability - Microsoft — Windows (Task Scheduler, Edge)
Vulnerable versions: all supported Windows versions with msedge.exe and Task Scheduler available
Fixed in: N/A
Remediation for APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and
Immediate actions
- Block or alert on outbound connections to webhook.site and similar generic webhook/request-bin services unless explicitly business-justified
- Disable Office macros for documents originating from the internet, or restrict execution to signed VBA only
- Hunt for scheduled tasks created in user-writable contexts that re-execute cmd.exe, wscript.exe, or a .bat/.vbs pair at 5-, 30-, or 61-minute intervals
Workarounds
- Restrict or closely monitor outbound HTTP/HTTPS traffic to *.webhook.site at the network egress boundary
Longer-term hardening
- Deploy EDR detections for msedge.exe launched with headless or hidden-window flags and no corresponding user activity
- Enforce FIDO2/hardware-key MFA for externally facing services used by diplomatic and government staff to blunt post-compromise credential reuse
- Build phishing-lure detection content for diplomatic-themed documents impersonating ministries or referencing recent bilateral meetings
Timeline of APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and
- HEADLACE, HOOKEDGE's direct predecessor, is in use by APT28/BlueDelta against diplomatic targets as early as April 2023.
- APT28 runs a HEADLACE campaign using a car-for-sale (Audi Q7) phishing decoy and DLL sideloading via a trojanized calculator binary to target diplomats.
- Earlier May 2024 HEADLACE campaigns target European networks with credential-harvesting components using the same malware family.
- The Hacker News publishes reporting on the HEADLACE car-sale-lure campaign, documenting APT28's webhook.site/Mocky-based C2 tradecraft.
- Spanish and Moldovan officials hold a bilateral meeting that is subsequently referenced in the earliest HOOKEDGE lure document.
- Earliest observed HOOKEDGE lure deployed, a macro-enabled Word document impersonating material from Spain's Ministry of the Presidency, Justice and Relations with the Cortes.
- BlueDelta shifts to generic 'Enable Content' lures with fake error dialogs, expanding targeting to Romanian government organizations through December 2025.
- Operators introduce a 'mailopened.jpg' webhook.site tracking canary alongside the existing 'docopened.jpg' canary to monitor the full phishing funnel.
- HOOKEDGE variants targeting Türkiye are identified, marking the campaign's geographic expansion and the end of the documented late-September-2025-to-early-April-2026 activity window.
- BlueDelta introduces minor VBA obfuscation changes to HOOKEDGE lure documents and removes the document-open tracking canary from later builds.
- Recorded Future's Insikt Group publishes its BlueDelta/HOOKEDGE research; The Hacker News and other outlets report on the campaign the same day.
Sources cited for APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and
- BlueDelta Targets Defense and Diplomacy with HOOKEDGE
- APT28-Linked HOOKEDGE Backdoor Targets Diplomatic Organizations in Romania, Spain, and Türkiye
- Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
- BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
- APT28 HOOKEDGE Backdoor Abuses Microsoft Edge and webhook.site for C2 and Data Exfiltration
- APT28 Targets Diplomats with HeadLace Malware via Car Sale Phishing Lure
- Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting
More in malware
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
Detection coverage for TL-2026-2213
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2213 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.