Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies, and diplomatic organizations in Romania, Spain, and Türkiye.

The campaign relied on Word documents designed to look routine or official, turning a familiar office file into an entry point for espionage.

Victims were asked to enable macros, small automated commands embedded in documents. That action launched a chain of scripts that installed the backdoor, set it to run again through Windows Task Scheduler, and gave operators a route to collect data.

Analysts at Recorded Future’s Insikt Group identified the activity as the work of BlueDelta, a Russia-linked group also known as APT28, Fancy Bear, and Forest Blizzard. They assess with moderate confidence that it supported Russian intelligence collection.

Recorded Future said in a report shared with Cyber Security News (CSN) that the campaign matters because it shows how a simple tool can be hard to spot when it uses services and software that are normally trusted.

Spain’s Ministry of the Presidency, Justice, and Relations with the Cortes document (Source - Recorded Future)
Spain’s Ministry of the Presidency, Justice, and Relations with the Cortes document (Source – Recorded Future)

HOOKEDGE sends its traffic through a public webhook service and Microsoft Edge, leaving fewer obvious warning signs than a conventional attacker-controlled server.

Russian Hackers Use New HOOKEDGE Malware

BlueDelta used macro-enabled Word attachments, likely delivered in spearphishing emails, to start the intrusion.

Early samples impersonated material connected to Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, while later files used generic prompts asking recipients to enable content. This resembles weaponized Office document campaigns tied to APT28.

Once macros ran, the document wrote files into the user’s profile folder and launched an installer. It then created a scheduled task and deleted much of the installation trail.

Unfamiliar tasks that start scripts from user-writable folders deserve attention, as Windows scheduled task abuse can give intruders lasting access.

HOOKEDGE is a lightweight Windows batch-script backdoor. On each check-in, it asks a staging endpoint for a command, rebuilds that command into a file, runs it, and sends the result to a separate endpoint.

It uses hidden Edge browser sessions for both steps, making malicious requests look closer to ordinary browsing activity. For selected victims, the operators installed a second HOOKEDGE instance that checked in as often as every five minutes, rather than every 30 minutes.

This suggests a triage model: broad access, then faster collection from higher-value victims. It also echoes the group’s broader use of cloud service command channels to hide operations among legitimate traffic.

HOOKEDGE is an evolution of its earlier HEADLACE backdoor. The overlap covers batch scripting and browser-based communications.

Defenders Should Watch the Edges

The group refined the malware between September 2025 and April 2026, changing its lures, browser settings, and check-in timings.

In one important adjustment, the first-stage interval was extended to 61 minutes, a delay likely intended to outlast automated analysis systems that often observe a suspicious file for only an hour.

BlueDelta also used separate webhook endpoints to record email opens, document opens, commands, and stolen output. This structure helped operators measure which lures worked and preserve limited request quotas on the free service.

While public platforms are not malicious by themselves, organizations should review whether webhook services are needed and block unapproved use.

HOOKEDGE lure document (Source - Recorded Future)
HOOKEDGE lure document (Source – Recorded Future)

The report recommends blocking macros in documents downloaded from the internet where feasible, restricting unsigned VBA, and using phishing-resistant multifactor authentication.

Security teams should also investigate unusual Edge launches involving hidden or headless windows, local HTML files, or data URLs.

The technique is especially relevant as browser-led phishing attacks continue to blur the line between normal application activity and intrusion.

Incident-response teams should correlate suspicious document activity with new scheduled tasks, script interpreters, and outbound webhook connections.

Fast containment is important: HOOKEDGE is built to deliver follow-on commands, and a victim moved to the higher-frequency stage can give operators a much quicker path to ongoing surveillance.

They should preserve the original email and document, isolate affected hosts, and search for the published indicators before attackers can remove evidence or deploy a second-stage payload.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxp://webhook[.]site/1e72b758-79e4-4c1c-90ed-7a8dc118f105 HOOKEDGE-related webhook endpoint
URL hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg Document-open canary endpoint
URL hxxp://webhook[.]site/68d68fc7-aa94-4f2d-a727-d18fb40b0d69/docopened[.]jpg Document-open canary endpoint
URL hxxp://webhook[.]site/c1d8ba4a-f044-4454-8b1c-b6866518f92c/doc[.]jpg Document-open canary endpoint
URL hxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/docopened[.]jpg Document-open canary endpoint
URL hxxp://webhook[.]site/c29905ab-e5fa-446c-8958-4eab15d8fb80/mailopened[.]jpg Email-open canary endpoint
URL hxxp://webhook[.]site/c2e1be16-401b-4f60-8a0f-276b30417fda/docopened[.]jpg Document-open canary endpoint
URL hxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/docopened.jpg Document-open canary endpoint
URL hxxp://webhook[.]site/d63049e3-1cbe-474b-9005-237517af53a7/mailopened[.]jpg Email-open canary endpoint
URL hxxps://webhook[.]site/01d6a811-ae9a-4ecb-be3f-610075556304 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/272f1315-14d7-458c-a4ca-e2df423490b4 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/34f908b6-dd89-4600-b413-a29cd5e37a0b HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/36c9aecd-19f5-4564-a354-7708d947da8e HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7d HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/4e81a907-cc30-45c0-8bbd-5248e9f6dacd HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/4ef62d6a-90c0-4a70-8dd2-468879c70fd6 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/5744c020-a8d9-4755-abfb-cde6ccd450af HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/5dbed3be-f1c9-41e5-b5d5-e961d08b5fba HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/655a413e-4a66-4987-8f5b-f5cbfe34cdd6 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/68ff1679-974b-4d15-9ce0-799892c63f04 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/752c57b9-20d1-4990-a909-fd212ab71dcd HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/81f3d140-eb6e-4d72-a6ca-e6e952c3d9c2 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/82911ae6-ea27-4996-a664-2322e89da9ae HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/9f2837e2-8321-46a5-aee5-ccdda349f864 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/a3f4e990-0b2a-4f6a-a02e-c573005de3ee HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/a72d8905-b15f-4e95-9a8f-5e4bb7dc9b3d HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/bbdbf60c-8593-4660-9620-d3c0de24a8ab HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/c24a31e4-691e-4a7b-96af-037ae735d358 HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/cf25f91c-0a20-4339-834f-02f73e8bc75e HOOKEDGE-related webhook endpoint
URL hxxps://webhook[.]site/d993e113-a672-48aa-a382-64c5aaac56eb HOOKEDGE-related webhook endpoint
Filename cf25f91c-0a20-4339-834f-02f73e8bc75e.bat HOOKEDGE payload
Filename cf25f91c-0a20-4339-834f-02f73e8bc75e.vbs HOOKEDGE launcher
Filename cf25f91c-0a20-4339-834f-02f73e8bc75e.cmd Installer
Filename 5744c020-a8d9-4755-abfb-cde6ccd450af.vbs Installer launcher
Filename cf25f91c-0a20-4339-834f-02f73e8bc75e.htm Exfiltration staging header
Filename cf25f91c-0a20-4339-834f-02f73e8bc75e.xhtml Exfiltration staging footer
SHA-256 001b57368c10bee9e62374e3b3f232b113eb75a1f198243d43a5bb90e1d0f500 HOOKEDGE-related sample hash
SHA-256 206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991 HOOKEDGE-related sample hash
SHA-256 231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1 HOOKEDGE-related sample hash
SHA-256 2793e7caba2f9beecd9b01baf41b8cb79f5a1a083ddedc6602ff23996bdc3104 HOOKEDGE-related sample hash
SHA-256 2e320c457658d35a2bb7c420c53bdcc3916f01a7dd4572e5540e8fce923d201b HOOKEDGE-related sample hash
SHA-256 2e81945ba27108cc613a8aa6aca409ad6f5204e647d08dd9ef7c881c9d28667a HOOKEDGE-related sample hash
SHA-256 38f0e1e00d5c6d4afd96217556ba1dbe963298be4f9f0890fc1a7618bed009bd HOOKEDGE-related sample hash
SHA-256 58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e HOOKEDGE-related sample hash
SHA-256 5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a HOOKEDGE-related sample hash
SHA-256 74456a8d6042a4232071bee99e25d23046b993486d6d8a98ab296915bbb53395 HOOKEDGE-related sample hash
SHA-256 7d8e98c0e322110021ae6d89f1a3ea090ef0741cf35b040dd4d0426a502d4845 HOOKEDGE-related sample hash
SHA-256 877648c6ff448aa4efe1e3f004c089411285b8cb4139320e0dbec9d1d1bb3c77 HOOKEDGE-related sample hash
SHA-256 87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3 HOOKEDGE-related sample hash
SHA-256 8f18e02cbe1fa7abd280d2e070efe7af07e20cfe635f81140d6d347c292f8f44 HOOKEDGE-related sample hash
SHA-256 9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc HOOKEDGE-related sample hash
SHA-256 9c02d5429717001c55420730ee345c172e7ed89df3052b1e32b9bd122fce616d HOOKEDGE-related sample hash
SHA-256 aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360 HOOKEDGE-related sample hash
SHA-256 b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4 HOOKEDGE-related sample hash
SHA-256 b1d037e9ff070d9722b7b289629d9b64a08ec35fd843cc01d37e6db69781ddcb HOOKEDGE-related sample hash
SHA-256 b8a1494b68617de92a3f58af8ca49dda4e9894f24c718ff3b26897a340e45c80 HOOKEDGE-related sample hash
SHA-256 bfc008f57dca8c6bf341d9d7cf66cdad53faf8b1bcfbeded4593a60f129174b6 HOOKEDGE-related sample hash
SHA-256 c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44 HOOKEDGE-related sample hash
SHA-256 c6db004f2e8ff321d8a0e6d0134f2737d0f6ff79a4627a4b803ef926c107aa00 HOOKEDGE-related sample hash
SHA-256 df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6 HOOKEDGE-related sample hash
SHA-256 ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1 HOOKEDGE-related sample hash
SHA-256 f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca HOOKEDGE-related sample hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets appeared first on Cyber Security News.