Russian APT28 Campaign Leveraging HOOKEDGE and webhook.site for European Espionage
Between September 2025 and April 2026, a Russian GRU-linked threat actor, identified as BlueDelta (overlapping with APT28), conducted a targeted espionage campaign against defense and diplomatic organizations in Romania, Spain, and Trkiye. The attackers deployed "HOOKEDGE," a lightweight Windows batch script backdoor designed for stealthy command-and-control (C2). The campaign utilizes the legitimate developer utility webhook.site for C2 infrastructure and employs traffic masking techniques to mimic standard Microsoft Edge browser activity. This approach effectively bypasses traditional network security monitoring by blending malicious telemetry with benign web traffic, facilitating long-term persistence and data exfiltration from high-value geopolitical targets.