< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Cybersecurity researchers expose Blind Eagle and APT28 malware campaigns

Cybersecurity investigations have revealed two distinct major malware campaigns. One investigation uncovered the infrastructure of a Blind Eagle-linked operation targeting Colombia and the wider region. The breach occurred after an attacker's workstation was infected by an information-stealing program, exposing remote-access tools (RATs), phishing kits, and credentials. The attackers used phishing emails impersonating judicial and traffic authorities, utilizing password-protected archives to evade automated scanning.

Separately, researchers identified a new backdoor named HOOKEDGE, attributed with moderate confidence to the Russian state-sponsored group APT28. This campaign targeted government and diplomatic organizations in Romania, Spain, and Türkiye between late 2025 and early 2026. The malware is delivered via macro-enabled Microsoft Word documents and uses webhook.site services for command-and-control and data exfiltration, allowing malicious traffic to blend in with legitimate network activity.

Entities

APT28 · Blind Eagle · LevelBlue · Recorded Future