APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
APT28-linked threat actors, tracked as BlueDelta, have been deploying a new backdoor named HOOKEDGE to target European government and diplomatic organizations since late 2025. HOOKEDGE, a lightweight Windows batch script, is delivered via macro-enabled Word documents and utilizes webhook[.]site for command-and-control, data exfiltration, and to bypass infrastructure limitations. The group has refined this tool over the past year, adapting it to evade detection and maintain operational resilience against evolving defenses. This represents a continued effort by APT28 to gather intelligence from European government and diplomatic targets.
APT28-linked threat actors, tracked as BlueDelta, have been deploying a new backdoor named HOOKEDGE to target European government and diplomatic organizations since late 2025. HOOKEDGE, a lightweight Windows batch script, is delivered via macro-enabled Word documents and utilizes webhook[.]site for command-and-control, data exfiltration, and to bypass infrastructure limitations. The group has refined this tool over the past year, adapting it to evade detection and maintain operational resilience against evolving defenses. This represents a continued effort by APT28 to gather intelligence from European government and diplomatic targets.
HOOKEDGE is distributed through macro-enabled Microsoft Word documents that prompt users to enable content to display the malicious payload. Upon execution, the script creates a scheduled task that runs every 30 minutes, executing the HOOKEDGE launcher and fetching arbitrary .cmd payloads from a staging webhook. The script then deletes itself and associated files to minimize forensic traces and complicate incident response.
The primary delivery mechanism is a Word document that, when opened, triggers the macro to write six files to the user profile directory and launch the HOOKEDGE installer chain. The script utilizes webhook[.]site for C2, payload staging, and data exfiltration, allowing malicious activity to blend in with regular network traffic and avoid dedicated infrastructure setup.
BlueDelta has observed a two-stage approach, with the initial implant focusing on broad initial access, followed by a second-stage payload deployed against high-value targets with a beaconing interval as little as five minutes. This separation of infrastructure is designed to overcome webhook[.]site's request limits, ensuring continued operational control and data collection.
BlueDelta has also removed a document-open canary, which previously captured victim IP addresses, likely to reduce network-based indicators of compromise. The group continues to adapt its tradecraft, emphasizing operational resilience by refining existing tools to counter evolving defensive measures and infrastructure constraints.
To counter this threat, organizations are recommended to prioritize blocking macro execution from internet-originated documents and implement detection coverage for scheduled task abuse, headless Microsoft Edge execution, and outbound connections to webhook services.
