GBHackers

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe


Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOOKEDGE in espionage operations targeting government, diplomatic, and defense-manufacturing organizations across Europe.

The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026.

New variants identified during June and July 2026 show that the group continues refining its phishing lures, malware execution chain, and command-and-control (C2) methods.

Russian Hackers Deploy New HOOKEDGE Backdoor

BlueDelta reportedly distributed macro-enabled Microsoft Word files through spearphishing campaigns. Early lures impersonated diplomatic material, including documents resembling communications from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.

Later samples used more generic documents containing junk text and prompts instructing recipients to click “Enable Content.” If a target enabled macros, the document’s AutoOpen() routine dropped multiple batch, command, VBScript, HTML, and XHTML files into the %userprofile% directory.

The malicious document also displayed a fake Microsoft Word error message, likely intended to make victims believe the file failed to open and to reduce scrutiny of the underlying execution.

HOOKEDGE is a polling backdoor built primarily around Windows batch scripting and legitimate software. It creates a scheduled task for persistence, then periodically uses Microsoft Edge to communicate with attacker-controlled endpoints hosted on webhook[.]site.

During each beaconing cycle, the malware removes selected download artifacts, retrieves attacker commands from a staging webhook, combines them into a .cmd payload, and executes the resulting script.

It then captures command output, packages it into an HTML file, and sends the resulting file to a separate webhook endpoint via an HTTP POST request.

Using msedge.exe as its HTTP client allows malicious traffic to blend in with ordinary HTTPS browser activity. Rather than operating dedicated C2 servers, BlueDelta relies on a legitimate third-party service that can create disposable endpoints with minimal infrastructure investment.

The group also used NordVPN IP addresses to administer the observed webhook endpoints, further complicating efforts to attribute or block the operator’s infrastructure.

Recorded Future assessed that BlueDelta uses HOOKEDGE to triage victims after initial compromise. First-stage payloads were configured to communicate at relatively low frequency, including intervals of 30 minutes and, in one later configuration, 61 minutes.

Selected victims received a second HOOKEDGE instance configured to beacon every 5 minutes. This approach gives operators faster tasking and response capabilities against systems judged to hold higher intelligence value, while maintaining a quieter footprint across lower-priority compromises.

Polyswarm stated that the 61-minute interval may also help the malware evade automated sandboxes that monitor suspicious programs for about an hour. It also reduces API request consumption on webhook[.]site, whose free tier limits requests per endpoint.

Researchers linked HOOKEDGE to BlueDelta with moderate confidence due to substantial technical and operational overlap with the group’s earlier HEADLACE backdoor.

Both malware families use batch-based execution, browser-mediated communications, legitimate internet services, hidden execution techniques, and similarly structured JavaScript payloads. The campaign underlines how state-backed espionage actors can achieve effective access and collection without complex malware.

Defenders should monitor macro-enabled attachments, suspicious scheduled tasks, hidden Edge executions, unusual browser requests to webhook services, and repeated creation of temporary batch or HTML files in user-profile directories.

IOCs

SHA-256 Hash
206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991
231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1
58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e
5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a
87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3
9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc
aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4
c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44
df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6
ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1
f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection



Source link