← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 7, 2026 · 07:42via Cyber Security News

Russian Hackers Use New HOOKEDGE Backdoor to Spy on European Organizations

Brief

Russian hackers have used a Windows backdoor called HOOKEDGE in espionage operations against diplomatic, government, and defense-related organizations across Europe.

The activity focused on targets in Romania, Spain, and Turkey, where seemingly ordinary Microsoft Word attachments became the opening move in a staged intrusion.

The campaign relies on spearphishing emails carrying macro-enabled documents. Victims are urged to enable content, which launches hidden scripts while a fake Word error message tries to make the suspicious behavior seem routine. The approach turns one unsafe click into a persistent channel for remote spying.

PolySwarm said in a report shared with Cyber Security News (CSN) that HOOKEDGE uses familiar Windows features and a public webhook service to blend into normal web traffic.

Read more on Cyber Security News