Cybersecurity researchers have identified a new backdoor, dubbed HOOKEDGE, used in recent campaigns attributed to the Russian state-sponsored hacking group APT28 (also known as Fancy Bear and Forest Blizzard). These campaigns targeted government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.
HOOKEDGE is a lightweight Windows batch script delivered through macro-enabled Microsoft Word documents. These documents use diplomatic-themed lures to entice targets into enabling macros. Early versions impersonated Spanish government material before switching to a social engineering approach.
The backdoor establishes persistence by creating a scheduled task that runs every 30 minutes. It also attempts to cover its tracks by deleting installer files and task definitions to complicate forensic analysis.
Attribution to APT28 is based on significant code and tradecraft overlap between HOOKEDGE and HEADLACE, another modular Windows backdoor previously used by APT28. Both backdoors utilize webhook[.]site services for command-and-control, payload staging, and data exfiltration, allowing malicious activity to blend with regular network traffic.
HOOKEDGE is considered a direct evolutionary successor to HEADLACE, undergoing continuous refinement to evade automated sandbox environments and adapt to API limits on webhook[.]site.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new backdoor named HOOKEDGE has been deployed by the Russian state-sponsored hacking group APT28, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. This backdoor is a refined version of previous APT28 tools, designed to evade detection and maintain persistence in compromised networks.