Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies, and diplomatic organizations in Romania, Spain, and Türkiye.
The campaign relied on Word documents designed to look routine or official, turning a familiar office file into an entry point for espionage.
Victims were asked to enable macros, small automated commands embedded in documents. That action launched a chain of scripts that installed the backdoor, set it to run again through Windows Task Scheduler, and gave operators a route to collect data.
Analysts at Recorded Future’s Insikt Group identified the activity as the work of BlueDelta, a Russia-linked group also known as APT28, Fancy Bear, and Forest Blizzard. They assess with moderate confidence that it supported Russian intelligence collection.
Recorded Future said in a report shared with Cyber Security News (CSN) that the campaign matters because it shows how a simple tool can be hard to spot when it uses services and software that are normally trusted.
HOOKEDGE sends its traffic through a public webhook service and Microsoft Edge, leaving fewer obvious warning signs than a conventional attacker-controlled server.
BlueDelta used macro-enabled Word attachments, likely delivered in spearphishing emails, to start the intrusion.
Early samples impersonated material connected to Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, while later files used generic prompts asking recipients to enable content. This resembles weaponized Office document campaigns tied to APT28.
Once macros ran, the document wrote files into the user’s profile folder and launched an installer. It then created a scheduled task and deleted much of the installation trail.
Unfamiliar tasks that start scripts from user-writable folders deserve attention, as Windows scheduled task abuse can give intruders lasting access.
HOOKEDGE is a lightweight Windows batch-script backdoor. On each check-in, it asks a staging endpoint for a command, rebuilds that command into a file, runs it, and sends the result to a separate endpoint.
It uses hidden Edge browser sessions for both steps, making malicious requests look closer to ordinary browsing activity. For selected victims, the operators installed a second HOOKEDGE instance that checked in as often as every five minutes, rather than every 30 minutes.
This suggests a triage model: broad access, then faster collection from higher-value victims. It also echoes the group’s broader use of cloud service command channels to hide operations among legitimate traffic.
HOOKEDGE is an evolution of its earlier HEADLACE backdoor. The overlap covers batch scripting and browser-based communications.
The group refined the malware between September 2025 and April 2026, changing its lures, browser settings, and check-in timings.
In one important adjustment, the first-stage interval was extended to 61 minutes, a delay likely intended to outlast automated analysis systems that often observe a suspicious file for only an hour.
BlueDelta also used separate webhook endpoints to record email opens, document opens, commands, and stolen output. This structure helped operators measure which lures worked and preserve limited request quotas on the free service.
While public platforms are not malicious by themselves, organizations should review whether webhook services are needed and block unapproved use.
The report recommends blocking macros in documents downloaded from the internet where feasible, restricting unsigned VBA, and using phishing-resistant multifactor authentication.
Security teams should also investigate unusual Edge launches involving hidden or headless windows, local HTML files, or data URLs.
The technique is especially relevant as browser-led phishing attacks continue to blur the line between normal application activity and intrusion.
Incident-response teams should correlate suspicious document activity with new scheduled tasks, script interpreters, and outbound webhook connections.
Fast containment is important: HOOKEDGE is built to deliver follow-on commands, and a victim moved to the higher-frequency stage can give operators a much quicker path to ongoing surveillance.
They should preserve the original email and document, isolate affected hosts, and search for the published indicators before attackers can remove evidence or deploy a second-stage payload.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxp://webhook[.]site/1e72b758-79e4-4c1c-90ed-7a8dc118f105 | HOOKEDGE-related webhook endpoint |
| URL | hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg | Document-open canary endpoint |
| URL | hxxp://webhook[.]site/68d68fc7-aa94-4f2d-a727-d18fb40b0d69/docopened[.]jpg | Document-open canary endpoint |
| URL | hxxp://webhook[.]site/c1d8ba4a-f044-4454-8b1c-b6866518f92c/doc[.]jpg | Document-open canary endpoint |
| URL | hxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/docopened[.]jpg | Document-open canary endpoint |
| URL | hxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/mailopened[.]jpg | Email-open canary endpoint |
| URL | hxxp://webhook[.]site/c2e1be16-401b-4f60-8a0f-276b30417fda/docopened[.]jpg | Document-open canary endpoint |
| URL | hxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/docopened.jpg | Document-open canary endpoint |
| URL | hxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/mailopened[.]jpg | Email-open canary endpoint |
| URL | hxxps://webhook[.]site/01d6a811-ae9a-4ecb-be3f-610075556304 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/272f1315-14d7-458c-a4ca-e2df423490b4 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/34f908b6-dd89-4600-b413-a29cd5e37a0b | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/36c9aecd-19f5-4564-a354-7708d947da8e | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7d | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/4e81a907-cc30-45c0-8bbd-5248e9f6dacd | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/4ef62d6a-90c0-4a70-8dd2-468879c70fd6 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/5744c020-a8d9-4755-abfb-cde6ccd450af | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/5dbed3be-f1c9-41e5-b5d5-e961d08b5fba | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/655a413e-4a66-4987-8f5b-f5cbfe34cdd6 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/68ff1679-974b-4d15-9ce0-799892c63f04 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/752c57b9-20d1-4990-a909-fd212ab71dcd | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/81f3d140-eb6e-4d72-a6ca-e6e952c3d9c2 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/82911ae6-ea27-4996-a664-2322e89da9ae | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/9f2837e2-8321-46a5-aee5-ccdda349f864 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/a3f4e990-0b2a-4f6a-a02e-c573005de3ee | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/a72d8905-b15f-4e95-9a8f-5e4bb7dc9b3d | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/bbdbf60c-8593-4660-9620-d3c0de24a8ab | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/c24a31e4-691e-4a7b-96af-037ae735d358 | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/cf25f91c-0a20-4339-834f-02f73e8bc75e | HOOKEDGE-related webhook endpoint |
| URL | hxxps://webhook[.]site/d993e113-a672-48aa-a382-64c5aaac56eb | HOOKEDGE-related webhook endpoint |
| Filename | cf25f91c-0a20-4339-834f-02f73e8bc75e.bat | HOOKEDGE payload |
| Filename | cf25f91c-0a20-4339-834f-02f73e8bc75e.vbs | HOOKEDGE launcher |
| Filename | cf25f91c-0a20-4339-834f-02f73e8bc75e.cmd | Installer |
| Filename | 5744c020-a8d9-4755-abfb-cde6ccd450af.vbs | Installer launcher |
| Filename | cf25f91c-0a20-4339-834f-02f73e8bc75e.htm | Exfiltration staging header |
| Filename | cf25f91c-0a20-4339-834f-02f73e8bc75e.xhtml | Exfiltration staging footer |
| SHA-256 | 001b57368c10bee9e62374e3b3f232b113eb75a1f198243d43a5bb90e1d0f500 | HOOKEDGE-related sample hash |
| SHA-256 | 206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991 | HOOKEDGE-related sample hash |
| SHA-256 | 231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1 | HOOKEDGE-related sample hash |
| SHA-256 | 2793e7caba2f9beecd9b01baf41b8cb79f5a1a083ddedc6602ff23996bdc3104 | HOOKEDGE-related sample hash |
| SHA-256 | 2e320c457658d35a2bb7c420c53bdcc3916f01a7dd4572e5540e8fce923d201b | HOOKEDGE-related sample hash |
| SHA-256 | 2e81945ba27108cc613a8aa6aca409ad6f5204e647d08dd9ef7c881c9d28667a | HOOKEDGE-related sample hash |
| SHA-256 | 38f0e1e00d5c6d4afd96217556ba1dbe963298be4f9f0890fc1a7618bed009bd | HOOKEDGE-related sample hash |
| SHA-256 | 58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e | HOOKEDGE-related sample hash |
| SHA-256 | 5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a | HOOKEDGE-related sample hash |
| SHA-256 | 74456a8d6042a4232071bee99e25d23046b993486d6d8a98ab296915bbb53395 | HOOKEDGE-related sample hash |
| SHA-256 | 7d8e98c0e322110021ae6d89f1a3ea090ef0741cf35b040dd4d0426a502d4845 | HOOKEDGE-related sample hash |
| SHA-256 | 877648c6ff448aa4efe1e3f004c089411285b8cb4139320e0dbec9d1d1bb3c77 | HOOKEDGE-related sample hash |
| SHA-256 | 87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3 | HOOKEDGE-related sample hash |
| SHA-256 | 8f18e02cbe1fa7abd280d2e070efe7af07e20cfe635f81140d6d347c292f8f44 | HOOKEDGE-related sample hash |
| SHA-256 | 9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc | HOOKEDGE-related sample hash |
| SHA-256 | 9c02d5429717001c55420730ee345c172e7ed89df3052b1e32b9bd122fce616d | HOOKEDGE-related sample hash |
| SHA-256 | aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360 | HOOKEDGE-related sample hash |
| SHA-256 | b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4 | HOOKEDGE-related sample hash |
| SHA-256 | b1d037e9ff070d9722b7b289629d9b64a08ec35fd843cc01d37e6db69781ddcb | HOOKEDGE-related sample hash |
| SHA-256 | b8a1494b68617de92a3f58af8ca49dda4e9894f24c718ff3b26897a340e45c80 | HOOKEDGE-related sample hash |
| SHA-256 | bfc008f57dca8c6bf341d9d7cf66cdad53faf8b1bcfbeded4593a60f129174b6 | HOOKEDGE-related sample hash |
| SHA-256 | c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44 | HOOKEDGE-related sample hash |
| SHA-256 | c6db004f2e8ff321d8a0e6d0134f2737d0f6ff79a4627a4b803ef926c107aa00 | HOOKEDGE-related sample hash |
| SHA-256 | df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6 | HOOKEDGE-related sample hash |
| SHA-256 | ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1 | HOOKEDGE-related sample hash |
| SHA-256 | f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca | HOOKEDGE-related sample hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…
Dark Caracal has returned with a new tool that helps attackers stay connected when defenders…
Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via…