Execution flow of a malicious Word document deploying HOOKEDGE | Image: Recorded Future
At a Glance
| Actor / group | BlueDelta (overlaps with APT28, Fancy Bear, Forest Blizzard) |
| Activity type | State-sponsored cyber espionage, initial access campaigns |
| Targets | Government, diplomatic, and defense organizations in Romania, Spain, and Turkiye |
| Scale | Multiple campaigns, September 2025 to April 2026 |
| Attribution status | Attributed with moderate confidence to Russia’s GRU |
| Source | Recorded Future Insikt Group (CTA-RU-2026-0827) |
TL;DR
Recorded Future’s Insikt Group linked a new backdoor called HOOKEDGE to the Russian group BlueDelta. The HOOKEDGE malware hit diplomatic and defense targets across Europe through booby-trapped Word documents. It abuses the legitimate webhook[.]site service to hide its traffic.
What Happened
Insikt Group found a run of BlueDelta initial access campaigns between late September 2025 and early April 2026. The attackers used macro-enabled Microsoft Word documents as bait. One early lure impersonated Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.
That document appeared soon after a September 2025 meeting between Spanish and Moldovan officials. The report notes the timing “may indicate an attempt to exploit legitimate diplomatic activity” of interest to Russia. Later campaigns dropped the diplomatic theme and used plain “Enable Content” prompts instead.
How the HOOKEDGE Malware Works
When a victim enables macros, the document drops six files and starts an installer chain. A scheduled task then runs every 30 minutes to keep the backdoor alive. The installer deletes itself to reduce forensic traces.
HOOKEDGE works as a polling loop. It pulls command payloads from one webhook, runs them, and sends output to a second webhook. Notably, it uses Microsoft Edge for both tasking and data theft. As the report puts it, the malware “blends its communications with normal enterprise browsing activity.”
For higher-value victims, BlueDelta deployed a second-stage payload. This version beaconed as often as every five minutes for faster, interactive control.
Who Is Behind It
Insikt Group attributes the activity to BlueDelta with moderate confidence. The group is a Russian state-sponsored actor tied to the GRU. Analysts base the call on code overlap with the older HEADLACE backdoor and consistent infrastructure patterns. Similar activity was reported publicly by Lab52 as Operation MacroMaze.
Impact and Scale
The campaigns focused on European governance, NATO-adjacent affairs, and Moldovan political matters. BlueDelta ran all C2, staging, and exfiltration through webhook[.]site’s free tier. It administered those endpoints from NordVPN addresses to blur attribution. The free tier’s 100-request cap shaped how the group timed its beacons and rotated endpoints.
How to Stay Protected
Insikt Group recommends blocking macros from internet-sourced documents. Security teams should watch for scheduled tasks that launch scripts from user folders. Unusual Microsoft Edge automation, such as headless launches opening local HTML, is another red flag.
Review outbound traffic to webhook and file-sharing services. Block those your organization does not use. Phishing-resistant MFA, like FIDO2 keys, also limits follow-on credential theft. The HOOKEDGE malware will likely evolve, so continued monitoring matters.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!