< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 4 sources · 7 days · First seen · Last updated

HOOKEDGE malware espionage campaign

Overview

Cybersecurity researchers have identified a malware campaign involving a new backdoor named HOOKEDGE. Initially attributed with moderate confidence to the Russian state-sponsored group APT28, the campaign has been linked to the Russian-linked threat actor BlueDelta.

The operation targets government, diplomatic, and defense organizations in Romania, Spain, and Türkiye. The attackers utilize spearphishing emails containing macro-enabled Microsoft Word documents. To evade detection, the malware employs several techniques: it displays fake Microsoft Word error messages to mask background activity, maintains persistence through Windows scheduled tasks, and leverages Microsoft Edge to communicate with attacker-controlled endpoints via public webhook services. This allows malicious traffic to blend in with legitimate HTTPS web browsing activity.

Entities

Recorded Future · LevelBlue · Blind Eagle · APT28

Timeline

  1. 6 days ago

    [TECHNOLOGY] 3 sources
    BlueDelta hackers deploy HOOKEDGE backdoor against European targets

    Russian-linked hackers have deployed the HOOKEDGE backdoor to spy on government and defense organizations in Romania, Spain, and Turkey using sophisticated spearphishing tactics.

  2. 13 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity researchers expose Blind Eagle and APT28 malware campaigns

    Cybersecurity researchers have exposed a Blind Eagle-linked phishing campaign and a new APT28-linked backdoor named HOOKEDGE targeting European government and diplomatic organizations.

Sources

clubic.com · cybernoz.com · infoguerra.com.br · invitehealth.substack.com