← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 28, 2026 · 15:07via Cyber Security News

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Brief

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies, and diplomatic organizations in Romania, Spain, and Türkiye.

The campaign relied on Word documents designed to look routine or official, turning a familiar office file into an entry point for espionage.

Victims were asked to enable macros, small automated commands embedded in documents. That action launched a chain of scripts that installed the backdoor, set it to run again through Windows Task Scheduler, and gave operators a route to collect data.

Analysts at Recorded Future’s Insikt Group identified the activity as the work of BlueDelta, a Russia-linked group also known as APT28, Fancy Bear, and Forest Blizzard. They assess with moderate confidence that it supported Russian intelligence collection.

Read more on Cyber Security News