{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/bluedelta/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["BlueDelta"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Word"],"_cs_severities":["high"],"_cs_tags":["espionage","windows","phishing","c2"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eBlueDelta, a Russian state-sponsored threat group also known as APT28, Fancy Bear, and Forest Blizzard, has been conducting a persistent espionage campaign against defense and diplomatic organizations in Romania, Spain, and Türkiye. Operational between September 2025 and April 2026, the campaign utilizes a lightweight, modular backdoor dubbed HOOKEDGE. This malware is a refined successor to the HEADLACE backdoor and is delivered via spearphishing campaigns using macro-enabled Microsoft Word documents.\u003c/p\u003e\n\u003cp\u003eThe HOOKEDGE implant is primarily composed of Windows batch scripts designed to execute commands and exfiltrate data by abusing legitimate internet services, specifically 'webhook[.]site'. This technique allows the group to blend malicious command-and-control (C2) traffic with normal network operations while maintaining a low footprint. The group has demonstrated significant tradecraft refinement during this period, including tailoring beaconing intervals based on target intelligence value to avoid detection and optimizing code to bypass sandbox environments. The use of diplomatic lures, including content impersonating the Spanish government, highlights the group's focus on intelligence collection aligned with Russian state interests.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established through spearphishing emails containing macro-enabled Microsoft Word documents.\u003c/li\u003e\n\u003cli\u003eThe user is prompted to enable content, triggering the execution of an embedded malicious VBA macro.\u003c/li\u003e\n\u003cli\u003eThe VBA macro drops and executes a Windows batch script (the HOOKEDGE backdoor) on the target host.\u003c/li\u003e\n\u003cli\u003eThe HOOKEDGE backdoor initiates persistence mechanisms, typically via the creation of malicious scheduled tasks.\u003c/li\u003e\n\u003cli\u003eThe backdoor performs environmental reconnaissance and determines its beaconing interval for the current session.\u003c/li\u003e\n\u003cli\u003eHOOKEDGE establishes C2 communication by sending HTTP requests to 'webhook[.]site' to retrieve follow-on commands or additional payloads.\u003c/li\u003e\n\u003cli\u003eThe malware executes secondary payloads or commands, potentially invoking headless Microsoft Edge instances to further interact with the environment.\u003c/li\u003e\n\u003cli\u003eStolen data is exfiltrated back through the same webhook infrastructure to conclude the collection mission.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign targets sensitive government and diplomatic communications, potentially resulting in the compromise of classified policy documents, strategic meeting agendas, and regional intelligence related to European parliamentary elections. Observed victims include personnel in Romania, Spain, and Türkiye. Successful exploitation provides the adversary with persistent, low-profile access for ongoing espionage, enabling the exfiltration of high-value intelligence over extended periods.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement Group Policy or Intune settings to block all macros in Office documents originating from the internet; this disrupts the primary delivery vector of HOOKEDGE.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon event ID 1 (Process Creation) and monitor for cmd.exe or powershell.exe spawned by WinWord.exe or Excel.exe.\u003c/li\u003e\n\u003cli\u003eMonitor for the creation of new scheduled tasks using 'schtasks.exe' or 'powershell.exe' immediately following the execution of Office applications.\u003c/li\u003e\n\u003cli\u003eDeploy network-level detection to flag outbound HTTP requests to known public webhook relay services like 'webhook[.]site'.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious headless execution of Microsoft Edge ('msedge.exe') from non-interactive or service-related accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T15:11:02Z","date_published":"2026-08-27T15:11:02Z","id":"https://feed.craftedsignal.io/briefs/2026-08-bluedelta-hookedge/","summary":"The Russian threat group BlueDelta is using a custom batch-script backdoor named HOOKEDGE to target European government and diplomatic entities via macro-enabled Microsoft Word documents that leverage legitimate webhook services for C2.","title":"BlueDelta Targets European Defense and Diplomacy with HOOKEDGE Backdoor","url":"https://feed.craftedsignal.io/briefs/2026-08-bluedelta-hookedge/"}],"language":"en","title":"CraftedSignal Threat Feed - BlueDelta","version":"https://jsonfeed.org/version/1.1"}