Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE.
The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute commands, and exfiltrate data.
BlueDelta overlaps with activity tracked publicly as APT28, Fancy Bear, and Microsoft’s Forest Blizzard, and is assessed to operate in support of Russia’s GRU military intelligence service.
The earliest observed lure, detected on September 26, 2025, impersonated an agenda from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes.
Researchers noted that the decoy appeared shortly after a September 2025 meeting involving Spanish and Moldovan officials, suggesting the operation may have been aligned with Russian intelligence requirements concerning Moldova’s political environment ahead of its parliamentary elections.
Later samples abandoned diplomatic themes in favor of generic documents that instructed recipients to click “Enable Content,” followed by a fake Microsoft Word error intended to suppress suspicion.
Once macros are enabled, the malicious document invokes an AutoOpen() routine that writes a batch payload, VBS launchers, an installer, and HTML fragments to the victim’s %userprofile% directory.
The installer creates a scheduled task for persistence, then deletes itself, its launcher, and the task-definition file to reduce the forensic footprint.
The remaining files use GUID-style names tied to BlueDelta’s webhook endpoints, linking the malware’s local artifacts directly to its tasking and exfiltration infrastructure.
Recorded Future’s Insikt Group attributed the campaigns to BlueDelta with moderate confidence, citing substantial overlap in code, infrastructure, and tradecraft with HEADLACE, an earlier batch-script implant associated with the group.
HOOKEDGE is not a conventional compiled malware family. Instead, it is a Windows batch-script backdoor built to poll attacker-controlled webhook[.]site endpoints for .cmd payloads.
It downloads command fragments, reconstructs them locally, executes the resulting command file, captures output, and packages the data inside a locally generated HTML page.
Microsoft Edge is then used to render that HTML file, causing an auto-submitting form to send the captured output to a separate webhook endpoint.
The approach turns a legitimate browser into the HTTP client for both command retrieval and exfiltration, allowing malicious traffic to resemble normal encrypted web browsing rather than traffic generated by an obvious command-and-control implant.
The group also used embedded remote-image references such as docopened[.]jpg and mailopened[.]jpg as tracking canaries.
These requests enabled operators to distinguish between email delivery, document opening, and successful macro execution providing campaign telemetry before deploying follow-on tooling.
Insikt Group assesses HOOKEDGE to be a direct evolution of HEADLACE, which BlueDelta used in multi-phase espionage activity across Europe during 2023.
Both malware families employ batch scripting, browser-mediated communications, legitimate internet services, GUID-based artifacts, and staged payload delivery.
Earlier HEADLACE operations also abused services including GitHub, Mocky, and InfinityFree, underlining BlueDelta’s preference for external platforms over maintaining dedicated adversary infrastructure.
The actor refined HOOKEDGE throughout the campaign. It shifted Edge execution from headless mode to hidden or off-screen browser windows, introduced phishing email-open tracking, modified VBA obfuscation, and extended first-stage beaconing to 61 minutes.
The longer interval likely helps evade sandboxes that observe suspicious processes for only an hour while preserving the limited request allowance imposed by webhook[.]site’s free tier.
For higher-value victims, BlueDelta deployed a second HOOKEDGE stage that beaconed as often as every five minutes.
This tiered model allows operators to use low-frequency malware for broad access and selectively move confirmed, intelligence-relevant victims to more responsive tasking infrastructure.
The campaign illustrates that operationally mature espionage does not require sophisticated binaries.
BlueDelta combines malicious Office macros, scheduled tasks, VBScript, batch files, Microsoft Edge, and webhook services into an evasive chain that is inexpensive and rapidly adaptable.
Defenders should block macros in internet-originated documents, investigate schtasks activity that launches scripts from user-writable paths, and scrutinize unusual Edge executions involving –headless, hidden windows, local HTML files, or data URLs.
Security teams should also baseline and restrict outbound access to webhook services where they lack a legitimate business purpose, while hunting for GUID-named .bat, .vbs, .cmd, .htm, and .xhtml files in user profile directories.
Lab52 separately tracked closely related activity as Operation MacroMaze, documenting similar Spanish-government lures, webhook-based document-open tracking, scheduled-task persistence, and browser-driven data exfiltration further reinforcing the continuity of the campaign’s tradecraft.
| # | Indicator type | Defanged URL |
|---|---|---|
| 1 | Webhook / callback URL | hxxps://webhook[.]site/01d6a811-ae9a-4ecb-be3f-610075556304 |
| 2 | Webhook / callback URL | hxxps://webhook[.]site/272f1315-14d7-458c-a4ca-e2df423490b4 |
| 3 | Webhook / callback URL | hxxps://webhook[.]site/34f908b6-dd89-4600-b413-a29cd5e37a0b |
| 4 | Webhook / callback URL | hxxps://webhook[.]site/36c9aecd-19f5-4564-a354-7708d947da8e |
| 5 | Webhook / callback URL | hxxps://webhook[.]site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7d |
| 6 | Webhook / callback URL | hxxps://webhook[.]site/4e81a907-cc30-45c0-8bbd-5248e9f6dacd |
| 7 | Webhook / callback URL | hxxps://webhook[.]site/4ef62d6a-90c0-4a70-8dd2-468879c70fd |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin,…
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform.…
A cyber incident reportedly forced a small UK power generation facility offline for about four…
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages…
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be…
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it…