APT28-linked HOOKEDGE backdoor targets diplomats
🛡️ Recorded Future's Insikt Group has identified campaigns from late September 2025 to April 2026 that delivered a newly observed Windows batch backdoor named HOOKEDGE via macro-enabled Word documents targeting government and diplomatic entities in Romania, Spain, and Türkiye. The activity is attributed with moderate confidence to APT28 (aka Fancy Bear), with HOOKEDGE exhibiting significant overlap with the group's earlier HEADLACE tooling and abusing webhook[.]site for C2, staging, and exfiltration.
