Cyber Security News

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies, and diplomatic organizations in Romania, Spain, and Türkiye.

The campaign relied on Word documents designed to look routine or official, turning a familiar office file into an entry point for espionage.

Victims were asked to enable macros, small automated commands embedded in documents. That action launched a chain of scripts that installed the backdoor, set it to run again through Windows Task Scheduler, and gave operators a route to collect data.

Analysts at Recorded Future’s Insikt Group identified the activity as the work of BlueDelta, a Russia-linked group also known as APT28, Fancy Bear, and Forest Blizzard. They assess with moderate confidence that it supported Russian intelligence collection.

Recorded Future said in a report shared with Cyber Security News (CSN) that the campaign matters because it shows how a simple tool can be hard to spot when it uses services and software that are normally trusted.

Spain’s Ministry of the Presidency, Justice, and Relations with the Cortes document (Source – Recorded Future)

HOOKEDGE sends its traffic through a public webhook service and Microsoft Edge, leaving fewer obvious warning signs than a conventional attacker-controlled server.

Russian Hackers Use New HOOKEDGE Malware

BlueDelta used macro-enabled Word attachments, likely delivered in spearphishing emails, to start the intrusion.

Early samples impersonated material connected to Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, while later files used generic prompts asking recipients to enable content. This resembles weaponized Office document campaigns tied to APT28.

Once macros ran, the document wrote files into the user’s profile folder and launched an installer. It then created a scheduled task and deleted much of the installation trail.

Unfamiliar tasks that start scripts from user-writable folders deserve attention, as Windows scheduled task abuse can give intruders lasting access.

HOOKEDGE is a lightweight Windows batch-script backdoor. On each check-in, it asks a staging endpoint for a command, rebuilds that command into a file, runs it, and sends the result to a separate endpoint.

It uses hidden Edge browser sessions for both steps, making malicious requests look closer to ordinary browsing activity. For selected victims, the operators installed a second HOOKEDGE instance that checked in as often as every five minutes, rather than every 30 minutes.

This suggests a triage model: broad access, then faster collection from higher-value victims. It also echoes the group’s broader use of cloud service command channels to hide operations among legitimate traffic.

HOOKEDGE is an evolution of its earlier HEADLACE backdoor. The overlap covers batch scripting and browser-based communications.

Defenders Should Watch the Edges

The group refined the malware between September 2025 and April 2026, changing its lures, browser settings, and check-in timings.

In one important adjustment, the first-stage interval was extended to 61 minutes, a delay likely intended to outlast automated analysis systems that often observe a suspicious file for only an hour.

BlueDelta also used separate webhook endpoints to record email opens, document opens, commands, and stolen output. This structure helped operators measure which lures worked and preserve limited request quotas on the free service.

While public platforms are not malicious by themselves, organizations should review whether webhook services are needed and block unapproved use.

HOOKEDGE lure document (Source – Recorded Future)

The report recommends blocking macros in documents downloaded from the internet where feasible, restricting unsigned VBA, and using phishing-resistant multifactor authentication.

Security teams should also investigate unusual Edge launches involving hidden or headless windows, local HTML files, or data URLs.

The technique is especially relevant as browser-led phishing attacks continue to blur the line between normal application activity and intrusion.

Incident-response teams should correlate suspicious document activity with new scheduled tasks, script interpreters, and outbound webhook connections.

Fast containment is important: HOOKEDGE is built to deliver follow-on commands, and a victim moved to the higher-frequency stage can give operators a much quicker path to ongoing surveillance.

They should preserve the original email and document, isolate affected hosts, and search for the published indicators before attackers can remove evidence or deploy a second-stage payload.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
URLhxxp://webhook[.]site/1e72b758-79e4-4c1c-90ed-7a8dc118f105HOOKEDGE-related webhook endpoint
URLhxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpgDocument-open canary endpoint
URLhxxp://webhook[.]site/68d68fc7-aa94-4f2d-a727-d18fb40b0d69/docopened[.]jpgDocument-open canary endpoint
URLhxxp://webhook[.]site/c1d8ba4a-f044-4454-8b1c-b6866518f92c/doc[.]jpgDocument-open canary endpoint
URLhxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/docopened[.]jpgDocument-open canary endpoint
URLhxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/mailopened[.]jpgEmail-open canary endpoint
URLhxxp://webhook[.]site/c2e1be16-401b-4f60-8a0f-276b30417fda/docopened[.]jpgDocument-open canary endpoint
URLhxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/docopened.jpgDocument-open canary endpoint
URLhxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/mailopened[.]jpgEmail-open canary endpoint
URLhxxps://webhook[.]site/01d6a811-ae9a-4ecb-be3f-610075556304HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/272f1315-14d7-458c-a4ca-e2df423490b4HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/34f908b6-dd89-4600-b413-a29cd5e37a0bHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/36c9aecd-19f5-4564-a354-7708d947da8eHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7dHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/4e81a907-cc30-45c0-8bbd-5248e9f6dacdHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/4ef62d6a-90c0-4a70-8dd2-468879c70fd6HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/5744c020-a8d9-4755-abfb-cde6ccd450afHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/5dbed3be-f1c9-41e5-b5d5-e961d08b5fbaHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/655a413e-4a66-4987-8f5b-f5cbfe34cdd6HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/68ff1679-974b-4d15-9ce0-799892c63f04HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/752c57b9-20d1-4990-a909-fd212ab71dcdHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/81f3d140-eb6e-4d72-a6ca-e6e952c3d9c2HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/82911ae6-ea27-4996-a664-2322e89da9aeHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/9f2837e2-8321-46a5-aee5-ccdda349f864HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/a3f4e990-0b2a-4f6a-a02e-c573005de3eeHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/a72d8905-b15f-4e95-9a8f-5e4bb7dc9b3dHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/bbdbf60c-8593-4660-9620-d3c0de24a8abHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/c24a31e4-691e-4a7b-96af-037ae735d358HOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/cf25f91c-0a20-4339-834f-02f73e8bc75eHOOKEDGE-related webhook endpoint
URLhxxps://webhook[.]site/d993e113-a672-48aa-a382-64c5aaac56ebHOOKEDGE-related webhook endpoint
Filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.batHOOKEDGE payload
Filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.vbsHOOKEDGE launcher
Filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.cmdInstaller
Filename5744c020-a8d9-4755-abfb-cde6ccd450af.vbsInstaller launcher
Filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.htmExfiltration staging header
Filenamecf25f91c-0a20-4339-834f-02f73e8bc75e.xhtmlExfiltration staging footer
SHA-256001b57368c10bee9e62374e3b3f232b113eb75a1f198243d43a5bb90e1d0f500HOOKEDGE-related sample hash
SHA-256206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991HOOKEDGE-related sample hash
SHA-256231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1HOOKEDGE-related sample hash
SHA-2562793e7caba2f9beecd9b01baf41b8cb79f5a1a083ddedc6602ff23996bdc3104HOOKEDGE-related sample hash
SHA-2562e320c457658d35a2bb7c420c53bdcc3916f01a7dd4572e5540e8fce923d201bHOOKEDGE-related sample hash
SHA-2562e81945ba27108cc613a8aa6aca409ad6f5204e647d08dd9ef7c881c9d28667aHOOKEDGE-related sample hash
SHA-25638f0e1e00d5c6d4afd96217556ba1dbe963298be4f9f0890fc1a7618bed009bdHOOKEDGE-related sample hash
SHA-25658cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577eHOOKEDGE-related sample hash
SHA-2565f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076aHOOKEDGE-related sample hash
SHA-25674456a8d6042a4232071bee99e25d23046b993486d6d8a98ab296915bbb53395HOOKEDGE-related sample hash
SHA-2567d8e98c0e322110021ae6d89f1a3ea090ef0741cf35b040dd4d0426a502d4845HOOKEDGE-related sample hash
SHA-256877648c6ff448aa4efe1e3f004c089411285b8cb4139320e0dbec9d1d1bb3c77HOOKEDGE-related sample hash
SHA-25687c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3HOOKEDGE-related sample hash
SHA-2568f18e02cbe1fa7abd280d2e070efe7af07e20cfe635f81140d6d347c292f8f44HOOKEDGE-related sample hash
SHA-2569097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fcHOOKEDGE-related sample hash
SHA-2569c02d5429717001c55420730ee345c172e7ed89df3052b1e32b9bd122fce616dHOOKEDGE-related sample hash
SHA-256aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360HOOKEDGE-related sample hash
SHA-256b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4HOOKEDGE-related sample hash
SHA-256b1d037e9ff070d9722b7b289629d9b64a08ec35fd843cc01d37e6db69781ddcbHOOKEDGE-related sample hash
SHA-256b8a1494b68617de92a3f58af8ca49dda4e9894f24c718ff3b26897a340e45c80HOOKEDGE-related sample hash
SHA-256bfc008f57dca8c6bf341d9d7cf66cdad53faf8b1bcfbeded4593a60f129174b6HOOKEDGE-related sample hash
SHA-256c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44HOOKEDGE-related sample hash
SHA-256c6db004f2e8ff321d8a0e6d0134f2737d0f6ff79a4627a4b803ef926c107aa00HOOKEDGE-related sample hash
SHA-256df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6HOOKEDGE-related sample hash
SHA-256ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1HOOKEDGE-related sample hash
SHA-256f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6caHOOKEDGE-related sample hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 minutes ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

2 hours ago

Hackers Use Fake Student Resume to Secretly Install Malware on Researchers’ Computers

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

3 hours ago

Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm

Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…

4 hours ago

Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption

Dark Caracal has returned with a new tool that helps attackers stay connected when defenders…

7 hours ago

Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code

Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via…

8 hours ago