negativeSYS.SOURCE: The Hacker News• 2026-08-28T13:50:59+05:30
APT28-Linked HOOKEDGE Backdoor Exploits Macro-Enabled Documents to Target European Diplomatic Entities
APT28-linked HOOKEDGE backdoor targets European government/diplomatic organizations through macro-enabled documents and webhook-based C2 infrastructure. The malware uses a two-stage architecture with scheduled task abuse and headless browser techniques to evade detection and maintain persistence.
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.
These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via
*** END OF TRANSMISSION ***