# HOOKEDGE malware espionage campaign

> Live situation record from CLSTR: https://clstr.news/situations/hookedge-malware-espionage-campaign
> Updated: 2026-09-06T19:52:00.000Z. Sources: 4. Developments: 2.

Cybersecurity researchers have identified a malware campaign involving a new backdoor named HOOKEDGE. Initially attributed with moderate confidence to the Russian state-sponsored group APT28, the campaign has been linked to the Russian-linked threat actor BlueDelta.

The operation targets government, diplomatic, and defense organizations in Romania, Spain, and Türkiye. The attackers utilize spearphishing emails containing macro-enabled Microsoft Word documents. To evade detection, the malware employs several techniques: it displays fake Microsoft Word error messages to mask background activity, maintains persistence through Windows scheduled tasks, and leverages Microsoft Edge to communicate with attacker-controlled endpoints via public webhook services. This allows malicious traffic to blend in with legitimate HTTPS web browsing activity.

## Timeline

### 2026-09-06: BlueDelta hackers deploy HOOKEDGE backdoor against European targets

Russian-linked hackers have deployed the HOOKEDGE backdoor to spy on government and defense organizations in Romania, Spain, and Turkey using sophisticated spearphishing tactics.

3 sources. https://clstr.news/cluster/bluedelta-hackers-deploy-hookedge-backdoor-against-european-targets

### 2026-08-30: Cybersecurity researchers expose Blind Eagle and APT28 malware campaigns

Cybersecurity researchers have exposed a Blind Eagle-linked phishing campaign and a new APT28-linked backdoor named HOOKEDGE targeting European government and diplomatic organizations.

2 sources. https://clstr.news/cluster/cybersecurity-researchers-expose-blind-eagle-and-apt28-malware-campaigns

---
Cite as: HOOKEDGE malware espionage campaign. CLSTR, https://clstr.news/situations/hookedge-malware-espionage-campaign
