Friday , September 25 2026
HOOKEDGE

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called HOOKEDGE in spying activities aimed at government, diplomatic, and defense-making groups in Europe. The team at PolySwarm recorded an action that aimed at groups in Romania, Spain, and Turkey from late September 2025 to early April 2026.

New variants found in June and July 2026 show that the group keeps improving its phishing tricks, malware delivery process, and command-and-control (C2) techniques.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Russian Hackers Deploy New HOOKEDGE Backdoor

BlueDelta reportedly distributed macro-enabled Microsoft Word files through spearphishing campaigns. Early lures impersonated diplomatic material, including documents resembling communications from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.

Later samples used more generic documents containing junk text and prompts instructing recipients to click “Enable Content.” If a target enabled macros, the document’s AutoOpen() routine dropped multiple batch, command, VBScript, HTML, and XHTML files into the %userprofile% directory.

The harmful document showed a fake Microsoft Word error message. This was probably meant to trick victims into thinking the file did not open and to lower the inspection of what was really happening.

HOOKEDGE is a backdoor that uses Windows batch scripts and real software. It sets up a scheduled task to stay active, and regularly uses Microsoft Edge to connect with attacker-run sites on webhook[.]site.

BookSecurity AuditsEvery time the malware activates, it deletes certain downloaded files, gets commands from a staging webhook, puts them together into a .cmd file, and runs the script.

It collects the command’s output, puts it into an HTML file, and sends that file to a different webhook endpoint using an HTTP POST request.

Using msedge.exe as its HTTP client allows malicious traffic to blend in with ordinary HTTPS browser activity. Rather than operating dedicated C2 servers, BlueDelta relies on a legitimate third-party service that can create disposable endpoints with minimal infrastructure investment.

The group used NordVPN IP addresses to manage the webhook endpoints. This made it harder to identify or stop the operator’s network.

Recorded Future found that BlueDelta uses HOOKEDGE to sort victims after they are first attacked. The first-stage payloads were set up to send messages at a low rate, like every 30 minutes and, in one later setting, every 61 minutes.

Selected victims got a second HOOKEDGE setup that signals every 5 minutes. This method lets operators act quicker and respond better to targets seen as more valuable, while keeping a lower profile with less important breaches.

Polyswarm said the 61-minute delay helps malware stay away from automated sandboxes that look for strange programs for about an hour. It also reduces API requests on webhook[.]site, which limits free requests for each endpoint.

Researchers connected HOOKEDGE to BlueDelta with moderate certainty because there is a lot of technical and operational similarity with the group’s earlier HEADLACE backdoor.

Both types of malware use batch files to run, communicate through browsers, use real internet services, hide their execution, and have similar JavaScript payloads. This campaign shows how state-sponsored spies can gain access and collect information without needing complex malware.

Defenders need to watch for attachments that can run macros, strange tasks set on a schedule, hidden Edge actions, odd browser requests to webhook services, and repeated making of temporary batch or HTML files in user folders.

IOCs

SHA-256 Hash
206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991
231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1
58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e
5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a
87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3
9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc
aebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4
c2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44
df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6
ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1
f611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca

Check Also

AI SOC

Gartner
70% of SOCs Will Pilot AI Agents: Only 15% Will See Results

The market for AI SOC agents is early, crowded, and full of claims that haven’t …