Urgent.News

What's breaking now, across thousands of outlets.

World

BlueDelta plants HOOKEDGE backdoor across European targets

A Russian state-linked cyber-espionage group has deployed a newly documented Windows backdoor, HOOKEDGE, against government, diplomatic and defence-related organisations in Romania, Spain and Türkiye, according to threat intelligence published in late August. Researchers at Recorded Future’s Insikt Group said the activity ran from late September 2025 to early April 2026 and was attributed with…

A recently uncovered Windows backdoor, dubbed HOOKEDGE, has been employed by a Russian state-backed cyber espionage group known as BlueDelta against various government, diplomatic, and defense organizations in Romania, Spain, and Türkiye, according to threat intelligence released in late August 2025. Recorded Future's Insikt Group attributed the activity to BlueDelta, a cluster that overlaps with APT28, Fancy Bear, and Forest Blizzard, a cyber group believed to be linked to Russia's GRU military intelligence service.

HOOKEDGE is a compact Windows batch-script implant delivered via macro-enabled Microsoft Word documents that impersonate official Spanish government material and exploit Microsoft Edge in hidden-window mode to receive commands and execute them through Windows command processes. The threat actors used webhook.site, a legitimate service for testing web requests, for command-and-control communication, payload delivery, and data exfiltration.

BlueDelta adapted their targeting approach to intelligence value, introducing a second-stage HOOKEDGE variant with a shorter beaconing interval for critical systems. The campaign began with a document mimicking Spain's Ministry of the Presidency, Justice, and Relations with the Cortes, following a September 2025 meeting involving Spanish and Moldovan officials, which led researchers to suspect a potential connection to Moldova's parliamentary election.

Between October and December 2025, the attackers shifted to less specific social-engineering documents, targeting organizations in Romania. The earliest activity identified by researchers occurred shortly after the September 2025 meeting, suggesting a possible link to intelligence requirements surrounding Moldova's parliamentary election.

Additional variants identified in early April 2026 were connected to organizations in Türkiye. While public reporting has not identified the victim organizations, there has been no confirmation from the affected governments. HOOKEDGE shares substantial code and operational similarities with HEADLACE, another malware family attributed to BlueDelta.

The consensus among European and allied cybersecurity authorities is that APT28 is likely Russia's GRU Unit 26165, known for conducting espionage operations against government, diplomatic, defense, and technology targets, including Ukraine and other NATO-linked interests.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in World

More from Saturday 5 September →