< Back to all clusters
[TECHNOLOGY] · Romania, Spain, Türkiye · 3 sources

started · updated

BlueDelta hackers deploy HOOKEDGE backdoor against European targets

Russian-linked threat actor BlueDelta has deployed a new Windows backdoor known as HOOKEDGE to conduct espionage against diplomatic, government, and defense organizations in Europe. Targeted entities include organizations in Romania, Spain, and Turkey.

The campaign utilizes spearphishing emails containing macro-enabled Microsoft Word documents. Once a victim enables content, the document executes an AutoOpen routine that writes various script and command files to the user profile directory. To evade detection, the malware displays a fake Microsoft Word error message, making the suspicious background activity appear to be a routine software failure.

HOOKEDGE is a polling backdoor that maintains persistence through Windows scheduled tasks. It leverages legitimate software, specifically Microsoft Edge, to communicate with attacker-controlled endpoints via a public webhook service. This method allows the malicious traffic to blend in with normal web browsing, making it difficult for security tools to distinguish the espionage activity from legitimate HTTPS traffic.