Executive Summary
A sophisticated cyber-espionage campaign has been identified targeting European government and diplomatic organizations, leveraging a novel backdoor known as HOOKEDGE. This campaign is attributed to the Russian state-sponsored threat actor APT28 (also known as Fancy Bear, Forest Blizzard, and BlueDelta). The attack chain utilizes macro-enabled Microsoft Word documents as the initial infection vector, delivering a lightweight batch-script-based backdoor that exploits legitimate cloud-based webhook infrastructure for command-and-control (C2) and data exfiltration. The campaign demonstrates advanced tradecraft, including multi-stage payload delivery, operational security enhancements, and rapid adaptation to detection efforts. The targeting of high-value governmental and diplomatic entities in Romania, Spain, and Türkiye underscores the persistent threat posed by APT28 to European critical infrastructure and sensitive political processes.
Threat Actor Profile
APT28 is a Russian state-sponsored advanced persistent threat group with a long history of targeting governmental, military, and diplomatic organizations across Europe and North America. The group is known for its sophisticated malware development, spear-phishing campaigns, and strategic intelligence collection objectives. APT28 has been linked to high-profile operations such as the 2016 US Democratic National Committee breach and numerous campaigns against NATO member states. The group’s modus operandi includes leveraging zero-day vulnerabilities, custom malware families (such as Sofacy, X-Agent, HEADLACE, and now HOOKEDGE), and exploiting trusted relationships within targeted sectors. APT28 is characterized by its rapid operational tempo, technical innovation, and ability to blend malicious activity with legitimate network traffic, complicating detection and attribution efforts.
Technical Analysis of Malware/TTPs
The HOOKEDGE backdoor represents a significant evolution in APT28’s toolkit, combining simplicity with operational stealth. The infection chain begins with macro-enabled Microsoft Word documents, typically themed around official government communications. Upon user interaction—specifically, enabling macros—the embedded VBA code writes multiple files to the victim’s %userprofile% directory. These files include batch scripts, Visual Basic scripts, and supporting artifacts necessary for the backdoor’s operation.
Persistence is established via the creation of a scheduled task, configured to execute the HOOKEDGE launcher at regular intervals (commonly every 30 or 61 minutes). The launcher, in turn, initiates the main backdoor component, which communicates with attacker-controlled endpoints hosted on webhook[.]site. This infrastructure is notable for its use of legitimate cloud webhook services, allowing malicious traffic to blend seamlessly with benign network activity and evade traditional perimeter defenses.
The backdoor’s core functionality includes polling the C2 server for command payloads (typically .cmd scripts), executing received instructions via the Windows command interpreter, and exfiltrating results as HTML files. Data exfiltration and C2 communications are conducted through Microsoft Edge running in headless or hidden mode, further obfuscating malicious activity. For high-value targets, a second-stage payload is deployed, reducing the beaconing interval to as little as five minutes and enabling more interactive attacker control.
Operational security enhancements observed in recent variants include the removal of document-open canaries (previously used to capture victim IP addresses), self-deletion of installer components, and the use of ephemeral scheduled tasks. The codebase exhibits significant overlap with the previously documented HEADLACE backdoor, indicating a shared development lineage and iterative refinement by APT28 operators.
Exploitation in the Wild
The HOOKEDGE campaign has been observed in active exploitation against government and diplomatic organizations in Romania, Spain, and Türkiye. Initial access is achieved through spear-phishing emails containing macro-enabled Word documents, often impersonating official correspondence from ministries or diplomatic entities. Upon successful compromise, the attackers deploy the HOOKEDGE backdoor, establish persistence, and begin staged data collection and exfiltration.
Threat intelligence sources, including Recorded Future and The Hacker News, have documented ongoing campaigns, with evidence of rapid tooling adaptation in response to detection and mitigation efforts. The use of webhook[.]site as C2 infrastructure has enabled APT28 to circumvent traditional network-based detection mechanisms, while the modular architecture of HOOKEDGE allows for tailored targeting and escalation against high-value victims. The campaign’s focus on governmental and diplomatic sectors highlights the strategic intelligence objectives of the threat actor and the elevated risk to European political and administrative processes.
Victimology and Targeting
The primary victims of the HOOKEDGE campaign are government ministries, diplomatic missions, and related agencies in Romania, Spain, and Türkiye. The targeting is highly selective, with spear-phishing lures crafted to mimic official communications relevant to the recipient’s role or organization. Analysis of lure documents reveals themes such as legislative updates, diplomatic correspondence, and inter-ministerial notifications.
The campaign demonstrates a clear focus on intelligence collection, with second-stage payloads and increased C2 beaconing frequency reserved for high-value targets. The use of legitimate cloud infrastructure for C2, combined with rapid operational adaptation, suggests a well-resourced and highly motivated adversary intent on maintaining persistent access to sensitive governmental and diplomatic networks.
Mitigation and Countermeasures
Organizations are strongly advised to implement a multi-layered defense strategy to mitigate the risk posed by HOOKEDGE and similar threats. Key recommendations include disabling macro execution for documents originating from external sources, monitoring for the creation and execution of scheduled tasks—particularly those invoking batch scripts from user-writable directories—and deploying endpoint detection and response (EDR) solutions capable of identifying anomalous process behavior, such as headless or hidden instances of Microsoft Edge.
Network monitoring should be configured to detect and alert on outbound connections to webhook[.]site and other cloud-based webhook services. Security teams should conduct proactive threat hunting for artifacts in the %userprofile% directory, unusual batch script activity, and the presence of suspicious scheduled tasks. Regular user awareness training is essential to reduce the risk of successful spear-phishing attacks, emphasizing the dangers of enabling macros in unsolicited documents.
Incident response plans should be updated to include procedures for identifying and remediating HOOKEDGE infections, including forensic analysis of affected endpoints, containment of compromised accounts, and notification of relevant authorities. Collaboration with threat intelligence providers and participation in information-sharing initiatives will enhance situational awareness and facilitate timely detection of emerging threats.
References
The Hacker News: APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Recorded Future: BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Security Affairs: Russian APT BlueDelta Uses HOOKEDGE
MITRE ATT&CK: APT28
webhook[.]site: https://webhook.site/
LinkedIn: Recorded Future on HOOKEDGE
Reddit: SecOpsDaily Discussion
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their extended supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify emerging threats, streamline risk assessments, and enhance organizational resilience. For more information about our solutions or to discuss your cybersecurity needs, we are happy to answer questions at info@rescana.com.



