Monday , September 7 2026
HOOKEDGE

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called HOOKEDGE in spying activities aimed at government, diplomatic, and defense-making groups in Europe. The team at PolySwarm recorded an action that aimed at groups in Romania, Spain, and Turkey from late September 2025 to early April 2026.

New variants found in June and July 2026 show that the group keeps improving its phishing tricks, malware delivery process, and command-and-control (C2) techniques.

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
India: C-DOT Launches 14 Local Quantum-Safe Technologies

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Microsoft has launched Project Zenith, a new Windows 11 experience for developers. It is made for powerful PCs that can...
Read More
Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws....
Read More
Google issues warning of new Chrome zero-day flaw exploited

CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

An unnamed security expert known as "Nightmare Eclipse" shared a CrowdStrike Falcon zero-day exploit called "FalconFlank." This tool allows hackers...
Read More
CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

727,000 data exposes: French hospital fined €500,000

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for not properly protecting the data...
Read More
727,000 data exposes: French hospital fined €500,000

Russian Hackers Deploy New HOOKEDGE Backdoor

BlueDelta reportedly distributed macro-enabled Microsoft Word files through spearphishing campaigns. Early lures impersonated diplomatic material, including documents resembling communications from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.

Later samples used more generic documents containing junk text and prompts instructing recipients to click “Enable Content.” If a target enabled macros, the document’s AutoOpen() routine dropped multiple batch, command, VBScript, HTML, and XHTML files into the %userprofile% directory.

The harmful document showed a fake Microsoft Word error message. This was probably meant to trick victims into thinking the file did not open and to lower the inspection of what was really happening.

HOOKEDGE is a backdoor that uses Windows batch scripts and real software. It sets up a scheduled task to stay active, and regularly uses Microsoft Edge to connect with attacker-run sites on webhook[.]site.

BookSecurity AuditsEvery time the malware activates, it deletes certain downloaded files, gets commands from a staging webhook, puts them together into a .cmd file, and runs the script.

It collects the command’s output, puts it into an HTML file, and sends that file to a different webhook endpoint using an HTTP POST request.

Using msedge.exe as its HTTP client allows malicious traffic to blend in with ordinary HTTPS browser activity. Rather than operating dedicated C2 servers, BlueDelta relies on a legitimate third-party service that can create disposable endpoints with minimal infrastructure investment.

The group used NordVPN IP addresses to manage the webhook endpoints. This made it harder to identify or stop the operator’s network.

Recorded Future found that BlueDelta uses HOOKEDGE to sort victims after they are first attacked. The first-stage payloads were set up to send messages at a low rate, like every 30 minutes and, in one later setting, every 61 minutes.

Selected victims got a second HOOKEDGE setup that signals every 5 minutes. This method lets operators act quicker and respond better to targets seen as more valuable, while keeping a lower profile with less important breaches.

Polyswarm said the 61-minute delay helps malware stay away from automated sandboxes that look for strange programs for about an hour. It also reduces API requests on webhook[.]site, which limits free requests for each endpoint.

Researchers connected HOOKEDGE to BlueDelta with moderate certainty because there is a lot of technical and operational similarity with the group’s earlier HEADLACE backdoor.

Both types of malware use batch files to run, communicate through browsers, use real internet services, hide their execution, and have similar JavaScript payloads. This campaign shows how state-sponsored spies can gain access and collect information without needing complex malware.

Defenders need to watch for attachments that can run macros, strange tasks set on a schedule, hidden Edge actions, odd browser requests to webhook services, and repeated making of temporary batch or HTML files in user folders.

IOCs

SHA-256 Hash
206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991
231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1
58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e
5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a
87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3
9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc
aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4
c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44
df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6
ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1
f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca

Check Also

200MW

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its …