Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called HOOKEDGE in spying activities aimed at government, diplomatic, and defense-making groups in Europe. The team at PolySwarm recorded an action that aimed at groups in Romania, Spain, and Turkey from late September 2025 to early April 2026.
New variants found in June and July 2026 show that the group keeps improving its phishing tricks, malware delivery process, and command-and-control (C2) techniques.
Russian Hackers Deploy New HOOKEDGE Backdoor
BlueDelta reportedly distributed macro-enabled Microsoft Word files through spearphishing campaigns. Early lures impersonated diplomatic material, including documents resembling communications from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.
Later samples used more generic documents containing junk text and prompts instructing recipients to click “Enable Content.” If a target enabled macros, the document’s AutoOpen() routine dropped multiple batch, command, VBScript, HTML, and XHTML files into the %userprofile% directory.
The harmful document showed a fake Microsoft Word error message. This was probably meant to trick victims into thinking the file did not open and to lower the inspection of what was really happening.
HOOKEDGE is a backdoor that uses Windows batch scripts and real software. It sets up a scheduled task to stay active, and regularly uses Microsoft Edge to connect with attacker-run sites on webhook[.]site.
BookSecurity AuditsEvery time the malware activates, it deletes certain downloaded files, gets commands from a staging webhook, puts them together into a .cmd file, and runs the script.
It collects the command’s output, puts it into an HTML file, and sends that file to a different webhook endpoint using an HTTP POST request.
Using msedge.exe as its HTTP client allows malicious traffic to blend in with ordinary HTTPS browser activity. Rather than operating dedicated C2 servers, BlueDelta relies on a legitimate third-party service that can create disposable endpoints with minimal infrastructure investment.
The group used NordVPN IP addresses to manage the webhook endpoints. This made it harder to identify or stop the operator’s network.
Recorded Future found that BlueDelta uses HOOKEDGE to sort victims after they are first attacked. The first-stage payloads were set up to send messages at a low rate, like every 30 minutes and, in one later setting, every 61 minutes.
Selected victims got a second HOOKEDGE setup that signals every 5 minutes. This method lets operators act quicker and respond better to targets seen as more valuable, while keeping a lower profile with less important breaches.
Polyswarm said the 61-minute delay helps malware stay away from automated sandboxes that look for strange programs for about an hour. It also reduces API requests on webhook[.]site, which limits free requests for each endpoint.
Researchers connected HOOKEDGE to BlueDelta with moderate certainty because there is a lot of technical and operational similarity with the group’s earlier HEADLACE backdoor.
Both types of malware use batch files to run, communicate through browsers, use real internet services, hide their execution, and have similar JavaScript payloads. This campaign shows how state-sponsored spies can gain access and collect information without needing complex malware.
Defenders need to watch for attachments that can run macros, strange tasks set on a schedule, hidden Edge actions, odd browser requests to webhook services, and repeated making of temporary batch or HTML files in user folders.
IOCs
| SHA-256 Hash |
|---|
206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991 |
231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1 |
58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e |
5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a |
87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3 |
9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc |
aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360 |
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4 |
c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44 |
df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6 |
ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1 |
f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca |
InfoSecBulletin Cybersecurity for mankind
