Cybersecurity researchers have uncovered a series of cyber espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. According to Recorded Future Insikt Group, the attacks involve a previously undocumented Windows backdoor known as HOOKEDGE, which is distributed through macro enabled Microsoft Word documents carrying diplomatic themed lures. Researchers stated that earlier versions of the campaign impersonated official Spanish government material before the operators shifted to a different social engineering approach about a month later. The activity has been attributed with moderate confidence to the Russian state sponsored threat group APT28, also known as Fancy Bear and Forest Blizzard, which Recorded Future tracks as BlueDelta.
Recorded Future based its attribution on notable similarities between HOOKEDGE and HEADLACE, a modular Windows backdoor that APT28 has used in campaigns targeting diplomats since April 2023. Researchers identified overlapping code structures, operational techniques, and the continued use of webhook.site services for command and control communications, payload staging, and data exfiltration. By relying on webhook services instead of dedicated command and control infrastructure, the attackers are able to blend malicious network traffic with legitimate activity while reducing infrastructure requirements. According to the researchers, HOOKEDGE has undergone continuous refinement between September 2025 and April 2026 to improve its ability to evade automated sandbox analysis and adapt to limitations imposed by the free tier of webhook.site services. The malware is delivered through macro enabled Microsoft Word documents that prompt recipients to enable content before executing malicious macros. Once activated, the macro writes six files to the user’s profile directory and launches the HOOKEDGE installation process. The installer creates a scheduled task configured to execute every 30 minutes, ensuring persistence while deleting installation files and task definitions to reduce forensic evidence and complicate incident response efforts. Researchers also observed that the lure document contains a hidden image linked to a webhook.site URL, allowing the operators to receive notification immediately after the document is opened by a target.
The HOOKEDGE backdoor itself is described as a lightweight Windows batch script that repeatedly checks for instructions from a webhook staging server. It retrieves command files, executes them on compromised systems, and returns the collected output through HTTP requests made by launching Microsoft Edge in either headless mode or a hidden window. After transmitting the collected information, the malware deletes temporary files and terminates processes associated with the HOOKEDGE task identifier to further reduce its operational footprint. Recorded Future also observed the deployment of a second stage version of HOOKEDGE against selected high value targets. Unlike the first stage implant, which communicates every 30 minutes, the second stage variant can reduce its beaconing interval to as little as five minutes, allowing operators to interact with compromised systems more efficiently. Researchers explained that this two stage architecture also helps the attackers work around webhook.site free tier limitations, which restrict each endpoint to 100 requests. By assigning high priority victims to separate webhook endpoints, the operators can continue intelligence collection without exhausting the initial infrastructure used for broader targeting.
Researchers believe the campaign demonstrates BlueDelta’s continued investment in lightweight and adaptable tools for intelligence gathering against European government and diplomatic organizations. Instead of introducing entirely new malware capabilities, the group has focused on refining existing techniques and modifying operational methods to improve resilience against defensive measures. Recorded Future also observed that the operators removed the document open canary previously used to capture victim IP addresses, a change that may reduce detectable network indicators during attacks. To reduce the risk posed by these campaigns, security teams are advised to block the execution of macros in documents originating from the internet, monitor systems for scheduled task abuse, detect headless Microsoft Edge execution, and inspect outbound connections to webhook based services. Researchers stated that the continued evolution of HOOKEDGE reflects the group’s ongoing efforts to adapt established malware and infrastructure to changing security environments while maintaining long term intelligence collection operations against government and diplomatic entities.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





