← Back to Daily Briefing (#NimbusManticore)

Between September 2025 and April 2026, a Russian GRU-linked threat actor, identified as BlueDelta (overlapping with APT28), conducted a targeted espionage campaign against defense and diplomatic organizations in Romania, Spain, and Trkiye. The attackers deployed "HOOKEDGE," a lightweight Windows batch script backdoor designed for stealthy command-and-control (C2). The campaign utilizes the legitimate developer utility webhook.site for C2 infrastructure and employs traffic masking techniques to mimic standard Microsoft Edge browser activity. This approach effectively bypasses traditional network security monitoring by blending malicious telemetry with benign web traffic, facilitating long-term persistence and data exfiltration from high-value geopolitical targets.

  • Incident Overview: European Espionage Operations

    • Target Sectors: Highly sensitive Government, Diplomatic, and Defense organizations.
    • Affected Regions: Romania, Spain, and Trkiye.
    • Campaign Duration: Active from late September 2025 through early April 2026.
  • Attack Mechanics: The HOOKEDGE Framework

    • Malware Profile: A lightweight Windows batch script backdoor designed to minimize the forensic footprint.
    • C2 Infrastructure: Leveraging webhook.site to intercept and facilitate HTTP-based command-and-control communications.
    • Evasion Strategy: Masking malicious C2 telemetry as legitimate Microsoft Edge browser traffic to bypass network behavioral analytics.
    • Stealth Tactics: Utilizing legitimate developer-centric tools to blend into standard enterprise web traffic.
  • Threat Actor Profile: BlueDelta / APT28

    • Attribution: Identified as BlueDelta, a group demonstrating significant operational overlap with APT28 (Russian GRU).
    • Motivation: State-sponsored strategic espionage aimed at gathering intelligence from European defense and diplomatic entities.
    • Sophistication: High; utilizes "living-off-the-land" (LotL) techniques and legitimate cloud services to avoid signature-based detection.
  • Defensive Actions: Detection and Mitigation

    • Network Monitoring: Implement scrutiny for anomalous outbound HTTP/S traffic directed toward webhook.site from sensitive workstations.
    • Endpoint Detection: Monitor for unauthorized or unusual execution of Windows batch scripts (.bat, .cmd) attempting external network connections.
    • Traffic Analysis: Correlate Microsoft Edge process activity with irregular destination patterns or non-standard request headers.
    • Egress Control: Restrict access to known web-testing and developer utility domains within critical defense and diplomatic network segments.
  • Conclusion: Strategic Implications

    • Threat Evolution: Demonstrates an increasing reliance on lightweight, non-binary payloads to evade traditional EDR/AV solutions.
    • Operational Risk: Highlights the risk of "living-off-the-cloud" tactics where legitimate SaaS tools are weaponized for C2.

Related posts

  1. Cybersecurity News — Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets
  2. The Record by Recorded Future — Australia charges two men for TeamPCP supply-chain hacking spree
  3. news.risky.biz — Risky Bulletin: Two TeamPCP members arrested in Australia
  4. feeds.feedburner.com — APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
  5. Security Affairs — Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
  6. Gbhackers

LINK COPIED TO CLIPBOARD