Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOOKEDGE in espionage operations targeting government, diplomatic, and defense-manufacturing organizations across Europe.
The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026.
New variants identified during June and July 2026 show that the group continues refining its phishing lures, malware execution chain, and command-and-control (C2) methods.
Russian Hackers Deploy New HOOKEDGE Backdoor
BlueDelta reportedly distributed macro-enabled Microsoft Word files through spearphishing campaigns. Early lures impersonated diplomatic material, including documents resembling communications from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.
Later samples used more generic documents containing junk text and prompts instructing recipients to click “Enable Content.” If a target enabled macros, the document’s AutoOpen() routine dropped multiple batch, command, VBScript, HTML, and XHTML files into the %userprofile% directory.
The malicious document also displayed a fake Microsoft Word error message, likely intended to make victims believe the file failed to open and to reduce scrutiny of the underlying execution.
HOOKEDGE is a polling backdoor built primarily around Windows batch scripting and legitimate software. It creates a scheduled task for persistence, then periodically uses Microsoft Edge to communicate with attacker-controlled endpoints hosted on webhook[.]site.
During each beaconing cycle, the malware removes selected download artifacts, retrieves attacker commands from a staging webhook, combines them into a .cmd payload, and executes the resulting script.
It then captures command output, packages it into an HTML file, and sends the resulting file to a separate webhook endpoint via an HTTP POST request.
Using msedge.exe as its HTTP client allows malicious traffic to blend in with ordinary HTTPS browser activity. Rather than operating dedicated C2 servers, BlueDelta relies on a legitimate third-party service that can create disposable endpoints with minimal infrastructure investment.
The group also used NordVPN IP addresses to administer the observed webhook endpoints, further complicating efforts to attribute or block the operator’s infrastructure.
Recorded Future assessed that BlueDelta uses HOOKEDGE to triage victims after initial compromise. First-stage payloads were configured to communicate at relatively low frequency, including intervals of 30 minutes and, in one later configuration, 61 minutes.
Selected victims received a second HOOKEDGE instance configured to beacon every 5 minutes. This approach gives operators faster tasking and response capabilities against systems judged to hold higher intelligence value, while maintaining a quieter footprint across lower-priority compromises.
Polyswarm stated that the 61-minute interval may also help the malware evade automated sandboxes that monitor suspicious programs for about an hour. It also reduces API request consumption on webhook[.]site, whose free tier limits requests per endpoint.
Researchers linked HOOKEDGE to BlueDelta with moderate confidence due to substantial technical and operational overlap with the group’s earlier HEADLACE backdoor.
Both malware families use batch-based execution, browser-mediated communications, legitimate internet services, hidden execution techniques, and similarly structured JavaScript payloads. The campaign underlines how state-backed espionage actors can achieve effective access and collection without complex malware.
Defenders should monitor macro-enabled attachments, suspicious scheduled tasks, hidden Edge executions, unusual browser requests to webhook services, and repeated creation of temporary batch or HTML files in user-profile directories.
IOCs
| SHA-256 Hash |
|---|
206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991 |
231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1 |
58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e |
5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a |
87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3 |
9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc |
aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360 |
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4 |
c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44 |
df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6 |
ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1 |
f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca |
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

