Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 4 sources · 7 days · First seen · Last updated
HOOKEDGE malware espionage campaign
Overview
Cybersecurity researchers have identified a malware campaign involving a new backdoor named HOOKEDGE. Initially attributed with moderate confidence to the Russian state-sponsored group APT28, the campaign has been linked to the Russian-linked threat actor BlueDelta.
The operation targets government, diplomatic, and defense organizations in Romania, Spain, and Türkiye. The attackers utilize spearphishing emails containing macro-enabled Microsoft Word documents. To evade detection, the malware employs several techniques: it displays fake Microsoft Word error messages to mask background activity, maintains persistence through Windows scheduled tasks, and leverages Microsoft Edge to communicate with attacker-controlled endpoints via public webhook services. This allows malicious traffic to blend in with legitimate HTTPS web browsing activity.
Entities
Timeline
-
6 days ago
[TECHNOLOGY] 3 sourcesBlueDelta hackers deploy HOOKEDGE backdoor against European targetsRussian-linked hackers have deployed the HOOKEDGE backdoor to spy on government and defense organizations in Romania, Spain, and Turkey using sophisticated spearphishing tactics.
-
13 days ago
[TECHNOLOGY] 2 sourcesCybersecurity researchers expose Blind Eagle and APT28 malware campaignsCybersecurity researchers have exposed a Blind Eagle-linked phishing campaign and a new APT28-linked backdoor named HOOKEDGE targeting European government and diplomatic organizations.
Sources
clubic.com · cybernoz.com · infoguerra.com.br · invitehealth.substack.com