Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
APT28’s HOOKEDGE Backdoor Targets European Entities

APT28’s HOOKEDGE Backdoor Targets European Entities

Posted on August 28, 2026 By CWS

Cybersecurity experts have identified new cyber campaigns targeting European government and diplomatic organizations, specifically in Romania, Spain, and Türkiye. These activities occurred between late September 2025 and early April 2026, marking a significant concern for cybersecurity within these regions.

Introduction of the HOOKEDGE Backdoor

Recorded Future’s Insikt Group has discovered a new backdoor tool called HOOKEDGE. This previously undocumented threat is a Windows batch script distributed via macro-enabled Microsoft Word documents. Initially, the attackers impersonated Spanish government documents before shifting to more sophisticated social engineering techniques.

The threat is linked to APT28, a Russian state-sponsored hacking group also known as Fancy Bear. The connection is made based on significant similarities between HOOKEDGE and an earlier backdoor known as HEADLACE, both used by APT28 in past cyber assaults on diplomats.

Technical Details and Impact

The HOOKEDGE backdoor uses Microsoft Word documents with embedded macros to infiltrate systems. When victims enable content, six files are written to the ‘%userprofile%’ directory, initiating the installation chain. The setup involves creating a scheduled task that runs every 30 minutes, executing the backdoor while erasing traces of its presence to hinder forensic investigations.

This backdoor also exploits webhook[.]site services for command-and-control operations. By blending malicious traffic with legitimate network activities, the attackers avoid setting up unique infrastructures, making detection more challenging.

Advanced Tactics and Future Outlook

BlueDelta, the group associated with APT28, has developed a two-stage deployment approach. The initial stage focuses on broad access, while the second stage targets high-value entities with more frequent beaconing intervals, ensuring sustained command-and-control capabilities without exhausting resources.

Based on evolving defensive strategies, APT28 has adapted its tactics, removing some initial indicators of compromise to better conceal their activities. Organizations are urged to block macro execution from external sources and monitor for scheduled task abuses and unusual network connections.

In conclusion, the ongoing threat posed by APT28 and its HOOKEDGE backdoor underscores the need for enhanced cybersecurity measures. Recorded Future emphasizes the importance of adapting to these persistent threats, highlighting the group’s focus on refining existing tools over introducing new ones, ensuring operational resilience amidst evolving defenses.

The Hacker News Tags:APT28, backdoor tool, BlueDelta, cyber attacks, cyber espionage, cyber threat, Cybersecurity, diplomatic organizations, European governments, HOOKEDGE, macro-enabled documents, Recorded Future, Russian hacking, webhook site

Post navigation

Previous Post: Cybersecurity Roundup: Log4j Concerns, Minimus Closure
Next Post: Russian Hackers Exploit New Malware to Target European Entities

Related Posts

Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack The Hacker News
Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection The Hacker News
Google’s August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild Google’s August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild The Hacker News
Cyberattack Hits Over 30 Minnesota Water Systems Cyberattack Hits Over 30 Minnesota Water Systems The Hacker News
Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data The Hacker News
Chinese Firms Linked to Silk Typhoon Filed 15+ Patents for Cyber Espionage Tools Chinese Firms Linked to Silk Typhoon Filed 15+ Patents for Cyber Espionage Tools The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Boosted Ransomware Analyzes Vast Data Quickly
  • Russian Hackers Exploit New Malware to Target European Entities
  • APT28’s HOOKEDGE Backdoor Targets European Entities
  • Cybersecurity Roundup: Log4j Concerns, Minimus Closure
  • Browser Extensions with Malicious Code Target Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Boosted Ransomware Analyzes Vast Data Quickly
  • Russian Hackers Exploit New Malware to Target European Entities
  • APT28’s HOOKEDGE Backdoor Targets European Entities
  • Cybersecurity Roundup: Log4j Concerns, Minimus Closure
  • Browser Extensions with Malicious Code Target Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark