Russian APT28-Linked Hackers Deploy HOOKEDGE Backdoor in European Espionage Attacks
Brief
Russian state-linked threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has used a lightweight Windows backdoor named HOOKEDGE in cyberespionage operations against European diplomatic, government, and defense-sector organizations.
Researchers linked the activity to targets in Romania, Spain, and Turkey, with campaign activity observed from late September 2025 through early April 2026 and newer variants emerging during June and July 2026.
According to Polyswarm , BlueDelta delivered HOOKEDGE through spearphishing attachments containing macro-enabled Microsoft Word documents.
Russian APT28-Linked Hackers Deploy HOOKEDGE Backdoor
Early lures used diplomatic themes, including a file impersonating material from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.
