CyberSecurity SEE

Russian Hackers Unleash HOOKEDGE Backdoor in Espionage Attacks Throughout Europe

Russian Hackers Unleash HOOKEDGE Backdoor in Espionage Attacks Throughout Europe

Russian Hackers Deploy New HOOKEDGE Backdoor Targeting European Entities

In a recent alarm raised by cybersecurity experts, the Russian state-sponsored threat actor known as BlueDelta, also referred to as APT28, Fancy Bear, and Forest Blizzard, has made significant advancements in its espionage techniques. This group has introduced a lightweight Windows backdoor named HOOKEDGE, which is currently being used in targeted operations against various governmental, diplomatic, and defense-manufacturing organizations throughout Europe.

The activities related to this new malware deployment were meticulously documented by PolySwarm, indicating that the operations focused primarily on entities located in Romania, Spain, and Turkey. The timeframe for these activities spanned from late September 2025 through early April 2026, suggesting a well-planned campaign aimed at gathering sensitive intelligence from these nations.

As the year progressed, researchers observed new variants of HOOKEDGE emerging in June and July 2026. These updates highlighted the group’s persistent evolution, as they refined their phishing methods, malware execution chains, and command-and-control (C2) strategies. This adaptability underscores the ongoing challenges faced by cybersecurity professionals tasked with defending against state-sponsored cyber threats.

BlueDelta’s use of macro-enabled Microsoft Word files as a key vector for launching spear-phishing campaigns warrants particular attention. Initially, the group employed lures that mimicked authentic diplomatic communications, notably documents purporting to come from Spain’s Ministry of the Presidency, Justice, and Relations with the Cortes. In subsequent iterations, the group resorted to broader, less specific documents that utilized nonsensical text, which included prompts urging recipients to click “Enable Content.”

Enabling macros would allow the document’s harmful AutoOpen() routine to execute. This routine would subsequently drop numerous threat files such as batch, command, VBScript, HTML, and XHTML into the targeted user’s profile directory. In a deceptive move, the malicious document would display a fake Microsoft Word error message, ostensibly to convince the victim that it had not opened correctly. This tactic was likely employed to mitigate any scrutiny surrounding the document’s underlying operations.

HOOKEDGE operates as a polling backdoor and is primarily constructed using Windows batch scripting alongside legitimate software tools. Its workings involve creating a scheduled task for persistence, allowing it to periodically utilize Microsoft Edge for communication with endpoints controlled by the attackers, hosted on the domain webhook[.]site.

During each beaconing cycle, HOOKEDGE cleans up previous download artifacts, retrieves commands set by the attacker from a designated webhook, consolidates those instructions into a .cmd payload, and proceeds to execute the resultant script. Captured command outputs are packaged into an HTML file and sent back to a separate webhook endpoint through an HTTP POST request.

A particularly sophisticated strategy employed by BlueDelta involves using msedge.exe as the HTTP client, enabling the malevolent traffic to blend seamlessly with usual HTTPS browser activity. This technique diverts attention and complicates detection efforts. Furthermore, rather than setting up dedicated C2 servers, BlueDelta has chosen to utilize a legitimate third-party service to create disposable endpoints, significantly reducing their infrastructural footprint.

Adding another layer of complexity to their operational security, the group has been observed using IP addresses from NordVPN to manage their webhook endpoints. This choice complicates attempts by cybersecurity experts to attribute activities or to block the underlying infrastructure.

Recorded Future has assessed the purpose of HOOKEDGE within the broader strategy used by BlueDelta. It appears to serve as a tool for triaging victims post-initial compromise. Early payload configurations were designed to communicate infrequently—at intervals of 30 minutes, and in a later configuration, up to 61 minutes. High-value targets received another instance of HOOKEDGE, designed to beacon every five minutes. This operational flexibility allows the operators to respond faster and manage tasks more efficiently, thereby prioritizing their activities based on intelligence value.

Insights from PolySwarm suggested that the 61-minute communication interval may also serve to thwart automated sandboxes, which typically monitor suspicious activities for approximately one hour. This helps the malware remain undetected longer while reducing API request consumption on webhook[.]site, which imposes limits on its free tier.

Researchers have been able to link HOOKEDGE with moderate confidence to BlueDelta due to significant technical similarities and operational patterns shared with the group’s earlier HEADLACE backdoor. Both malware variants utilize batch-based execution, browser-mediated communications, and hidden execution techniques, alongside similarly structured JavaScript payloads.

This campaign showcases how state-sponsored espionage actors can effectively access and gather intelligence without necessitating the use of highly complex malware. With the escalation of such espionage activities, it has become critical for defenders to keep a close watch on macro-enabled attachments, suspicious scheduled tasks, hidden executions of Edge, unusual browser requests directed at webhook services, and the recurrent creation of temporary batch or HTML files within user profile directories.

As the threat landscape continues to evolve, organizations are urged to enhance their vigilance and proactively monitor for these indicators, ensuring that they remain aware of active threats in real-time.

Source link

Exit mobile version