cyber securityCyber Security NewsMalware 4 min.Read BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware By Mayura Kathir August 28, 2026 Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute commands, and exfiltrate data. BlueDelta overlaps with activity tracked publicly as APT28, Fancy Bear, and Microsoft’s Forest Blizzard, and is assessed to operate in support of Russia’s GRU military intelligence service.
The earliest observed lure, detected on September 26, 2025, impersonated an agenda from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes. Researchers noted that the decoy appeared shortly after a September 2025 meeting involving Spanish and Moldovan officials, suggesting the operation may have been aligned with Russian intelligence requirements concerning Moldova’s political environment ahead of its parliamentary elections. Later samples abandoned diplomatic themes in favor of generic documents that instructed recipients to click “Enable Content,” followed by a fake Microsoft Word error intended to suppress suspicion.
Once macros are enabled, the malicious document invokes an AutoOpen() routine that writes a batch payload, VBS launchers, an installer, and HTML fragments to the victim’s %userprofile% directory. The installer creates a scheduled task for persistence, then deletes itself, its launcher, and the task-definition file to reduce the forensic footprint. HOOKEDGE lure document (Source : Insikt).
The remaining files use GUID-style names tied to BlueDelta’s webhook endpoints, linking the malware’s local artifacts directly to its tasking and exfiltration infrastructure. Recorded Future’s Insikt Group attributed the campaigns to BlueDelta with moderate confidence, citing substantial overlap in code, infrastructure, and tradecraft with HEADLACE, an earlier batch-script implant associated with the group. HOOKEDGE Malware Campaign HOOKEDGE is not a conventional compiled malware family.
Instead, it is a Windows batch-script backdoor built to poll attacker-controlled webhook[.]site endpoints for .cmd payloads. It downloads command fragments, reconstructs them locally, executes the resulting command file, captures output, and packages the data inside a locally generated HTML page. Execution flow of a malicious Word document deploying HOOKEDGE (Source : Insikt).
Microsoft Edge is then used to render that HTML file, causing an auto-submitting form to send the captured output to a separate webhook endpoint. The approach turns a legitimate browser into the HTTP client for both command retrieval and exfiltration, allowing malicious traffic to resemble normal encrypted web browsing rather than traffic generated by an obvious command-and-control implant. The group also used embedded remote-image references such as docopened[.]jpg and mailopened[.]jpg as tracking canaries.
These requests enabled operators to distinguish between email delivery, document opening, and successful macro execution providing campaign telemetry before deploying follow-on tooling. Insikt Group assesses HOOKEDGE to be a direct evolution of HEADLACE, which BlueDelta used in multi-phase espionage activity across Europe during 2023. Both malware families employ batch scripting, browser-mediated communications, legitimate internet services, GUID-based artifacts, and staged payload delivery.
Earlier HEADLACE operations also abused services including GitHub, Mocky, and InfinityFree, underlining BlueDelta’s preference for external platforms over maintaining dedicated adversary infrastructure. The actor refined HOOKEDGE throughout the campaign. It shifted Edge execution from headless mode to hidden or off-screen browser windows, introduced phishing email-open tracking, modified VBA obfuscation, and extended first-stage beaconing to 61 minutes.
The longer interval likely helps evade sandboxes that observe suspicious processes for only an hour while preserving the limited request allowance imposed by webhook[.]site’s free tier. For higher-value victims, BlueDelta deployed a second HOOKEDGE stage that beaconed as often as every five minutes. This tiered model allows operators to use low-frequency malware for broad access and selectively move confirmed, intelligence-relevant victims to more responsive tasking infrastructure.
The campaign illustrates that operationally mature espionage does not require sophisticated binaries. BlueDelta combines malicious Office macros, scheduled tasks, VBScript, batch files, Microsoft Edge, and webhook services into an evasive chain that is inexpensive and rapidly adaptable. Defenders should block macros in internet-originated documents, investigate schtasks activity that launches scripts from user-writable paths, and scrutinize unusual Edge executions involving –headless, hidden windows, local HTML files, or data URLs.
Security teams should also baseline and restrict outbound access to webhook services where they lack a legitimate business purpose, while hunting for GUID-named .bat, .vbs, .cmd, .htm, and .xhtml files in user profile directories. Lab52 separately tracked closely related activity as Operation MacroMaze, documenting similar Spanish-government lures, webhook-based document-open tracking, scheduled-task persistence, and browser-driven data exfiltration further reinforcing the continuity of the campaign’s tradecraft. IOCs #Indicator typeDefanged URL1Webhook / callback URLhxxps://webhook[.]site/01d6a811-ae9a-4ecb-be3f-6100755563042Webhook / callback URLhxxps://webhook[.]site/272f1315-14d7-458c-a4ca-e2df423490b43Webhook / callback URLhxxps://webhook[.]site/34f908b6-dd89-4600-b413-a29cd5e37a0b4Webhook / callback URLhxxps://webhook[.]site/36c9aecd-19f5-4564-a354-7708d947da8e5Webhook / callback URLhxxps://webhook[.]site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7d6Webhook / callback URLhxxps://webhook[.]site/4e81a907-cc30-45c0-8bbd-5248e9f6dacd7Webhook / callback URLhxxps://webhook[.]site/4ef62d6a-90c0-4a70-8dd2-468879c70fd Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking.
Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. ★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide Tagscyber securityCyber Security NewsMalware Mayura Kathirhttps://gbhackers.com/Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more. Hot this week Infosec- Resources How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities June 4, 2023 1 What is Deep Web The deep web, invisible web, or...
SOC Architecture How to Build and Run a Security Operations Center (SOC Guide) – 2023 June 3, 2023 12 Today’s Cyber security operations center (CSOC) should have everything... Cyber Security News Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component October 18, 2023 0 TeamViewer's popularity and remote access capabilities make it an... Checklist Web Server Penetration Testing Checklist – 2026 January 6, 2026 0 Web server pentesting is performed under three significant categories: identity,...
Infosec- Resources ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities June 4, 2023 4 ATM Penetration testing, Hackers have found different approaches to... TopicsAcquisitionAdobeAdwareAIAmazonAmazon AWSAMDAndroidAnti VirusAntimalwareANY RUNApacheAPIAppleAPTArtificial IntelligenceAvastAWSAzureBackdoorBitcoinBluetoothBotnetBrowserBuffer over flowBug BountyBusinessChatbotsChatGPTChecklistChromeCiscoCISOCISO AdvisoryCloudCloud SecurityCloudflareComputer SecurityCourseCPUCross site ScriptingcryptocurrencyCryptocurrency hackCVE/vulnerabilityCyber AdvisoryCyber AICyber AttackCyber Crimecyber securityCyber security CourseCyber Security NewsCyber Security ResourcesCybersecurity NewsletterDark WebData BreachData GovernanceDDOSDealsDeepSeekDiscordDNSDos AttackDriveDropboxEducationEmailEmail SecurityEthical HackingExploitExploitation ToolsExtratorrentsFACEBOOKFeaturedFirefoxFirefox NewsFirewallForensics ToolsgameGenAIGitHubGitLabGmailGoogleGoogle dorksGovernanceGRCHacking BooksHacksHardware HackingHBOHTMLHTTPIBMIISIncident ResponseInformation GatheringInformation Security RisksInfosec- ResourcesInsider ThreatsInstagramMore Bluetooth Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth 0 Security researcher Boschko has revealed two vulnerabilities in Unitree’s... AI TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation 0 A newly emerged ransomware-as-a-service operation named TITAN is advertising...
Cyber Security News Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code 0 A recent demonstration of prompt-injection research has revealed that... cyber security Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords. 0 Hundreds of compromised WordPress websites are being used in... Cyber Security News Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents 0 Corporate executives' Social Security numbers (SSNs) are being sold... cyber security Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory 0 A Windows malware campaign disguised as a graduate-school resume... cyber security Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations 0 A cache of leaked internal records has exposed what... cyber security Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected 0 Dark Caracal-linked operators are using Ethereum smart contracts as...
Related Articles Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth Bluetooth August 28, 2026 TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation AI August 28, 2026 Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code Cyber Security News August 28, 2026 Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords. cyber security August 28, 2026 Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents Cyber Security News August 28, 2026 Recent News Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth Divya - August 28, 2026 TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation Mayura Kathir - August 28, 2026 Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code Divya - August 28, 2026 Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords. Mayura Kathir - August 28, 2026 Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents Divya - August 28, 2026 Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory Mayura Kathir - August 28, 2026