← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

APT28 Deploys New HOOKEDGE Backdoor Against European Government and Diplomatic Entities

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • APT28 used HOOKEDGE backdoor in campaigns from late September 2025 to early April 2026.
  • Targets included government and diplomatic organizations in Romania, Spain, and Türkiye.
  • HOOKEDGE is a Windows batch script distributed via macro-enabled Word documents.
  • It shares code and tradecraft with APT28's HEADLACE backdoor.

New Backdoor Identified in APT28 Campaigns

Cybersecurity researchers have identified a new backdoor, dubbed HOOKEDGE, used in recent campaigns attributed to the Russian state-sponsored hacking group APT28 (also known as Fancy Bear and Forest Blizzard). These campaigns targeted government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.

Technical Details of HOOKEDGE

HOOKEDGE is a lightweight Windows batch script delivered through macro-enabled Microsoft Word documents. These documents use diplomatic-themed lures to entice targets into enabling macros. Early versions impersonated Spanish government material before switching to a social engineering approach.

The backdoor establishes persistence by creating a scheduled task that runs every 30 minutes. It also attempts to cover its tracks by deleting installer files and task definitions to complicate forensic analysis.

Attribution and Evolution

Attribution to APT28 is based on significant code and tradecraft overlap between HOOKEDGE and HEADLACE, another modular Windows backdoor previously used by APT28. Both backdoors utilize webhook[.]site services for command-and-control, payload staging, and data exfiltration, allowing malicious activity to blend with regular network traffic.

HOOKEDGE is considered a direct evolutionary successor to HEADLACE, undergoing continuous refinement to evade automated sandbox environments and adapt to API limits on webhook[.]site.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Aug 28

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new backdoor named HOOKEDGE has been deployed by the Russian state-sponsored hacking group APT28, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. This backdoor is a refined version of previous APT28 tools, designed to evade detection and maintain persistence in compromised networks.