Russian GRU-linked actor BlueDelta (APT28) conducted "Operation MacroMaze" between September 2025 and April 2026, targeting government and defense sectors in Romania, Spain, and Trkiye. The campaign utilizes spear-phishing emails containing malicious Microsoft Office macros to execute HOOKEDGE, a lightweight Windows batch script backdoor. To bypass network detection and security monitoring, the actor leverages webhook.site—a legitimate HTTP request testing service—as a Command and Control (C2) mechanism, masking malicious traffic by routing it through the Microsoft Edge browser. This technique significantly reduces the operational footprint and blends malicious C2 requests with legitimate developer traffic.
-
Incident Overview: Operation MacroMaze
- Targeted diplomatic and defense organizations specifically within Romania, Spain, and Trkiye.
- Operational window spanned from late September 2025 through early April 2026.
- Attributed to BlueDelta, a threat group identified as overlapping with the Russian GRU-linked APT28.
-
Attack Vector and Execution Mechanics
- Initial access is achieved via high-precision spear-phishing emails containing weaponized Microsoft Office documents.
- Execution relies on the activation of malicious macros to deploy the primary payload.
- The payload, HOOKEDGE, is a minimalist Windows batch script designed for initial access, persistence, and basic system control.
-
C2 Infrastructure and Evasion Techniques
- Employs
webhook.site, a legitimate developer tool for HTTP request testing, to serve as the C2 endpoint. - Routes outbound traffic through the Microsoft Edge browser to mimic legitimate user behavior and evade protocol anomalies.
- Utilizes lightweight script execution to minimize the on-disk footprint, effectively bypassing many signature-based EDR detections.
- Employs
-
Threat Actor Profile and Strategic Impact
- BlueDelta/APT28 demonstrates a strategic focus on long-term intelligence collection within European diplomatic channels.
- The campaign highlights a sophisticated shift toward "living-off-the-land" (LotL) techniques by weaponizing legitimate web services.
- Potential impact includes the exfiltration of sensitive diplomatic communications and strategic defense data.
-
Defensive Actions and Mitigation
- Implement strict organizational policies to disable Microsoft Office macros for files originating from the internet.
- Establish network monitoring alerts for anomalous outbound traffic to
webhook.siteand similar developer-centric HTTP utilities. - Audit process execution logs for suspicious
cmd.exeor batch file activity spawned directly from Office applications.
Related posts
- techjacksolutions.com — APT28 Deploys HOOKEDGE Backdoor in Webhook-Based Espionage Campaign Against European Diplomatic Targets
- The Record by Recorded Future — Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
- Cyfar
- feeds.feedburner.com — APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
- gbhackers.com — BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
- Security Affairs — Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
- Recordedfuture
- Cyberpress
- Rescana