Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Defense and Diplomacy Targeted with HOOKEDGE

0
Medium
Published: 08/27/2026 (08/27/2026, 17:37:41 UTC)
Source: AlienVault OTX General

Description

Between late September 2025 and early April 2026, BlueDelta conducted espionage campaigns against government and diplomatic organizations in Romania, Spain, and Türkiye. The threat group deployed HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents using diplomatic-themed lures, including material impersonating Spain's Ministry of the Presidency created after a September 2025 meeting between Spanish and Moldovan officials. HOOKEDGE shares significant code and tradecraft overlap with the previously documented HEADLACE backdoor, abusing legitimate webhook services for command-and-control, payload staging, and data exfiltration. The implant underwent continuous refinement to evade sandbox environments and adapt to webhook service limitations. BlueDelta employed a tiered operational model, deploying second-stage payloads with shorter beaconing intervals for high-value targets while preserving initial-access infrastructure.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge"]
Adversary
APT28
Pulse Id
6a9075e5bf883e170338fa51
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e
hash9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc
hashb0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4
hashdf60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6
hashed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1
hash7c103519b975225c26b3c73e56295dde
hash8473a9fb11f822ef738259d4528f9d25
hashb46cbc0a5405703f110218d4ee2e46eb
hashc9f3e6057e1809c10514f6a923a15860
hasheba56e503290204ab2bd77b130b3a1e4
hash2774b165fab2d2f61a709f4d0411a87fcde920d2
hash2dc99ef518c3c7fa62f26cd1cc6da9acb376b037
hash5da5bd587b6039940586a98088f868c31c0b7129
hashde037b7e5e93ba1f8f6933d479f1216a9f01ecb2
hashe4b61165be5937987b88352d2f1f8d57def30408
hash001b57368c10bee9e62374e3b3f232b113eb75a1f198243d43a5bb90e1d0f500
hash206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991
hash231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1
hash2793e7caba2f9beecd9b01baf41b8cb79f5a1a083ddedc6602ff23996bdc3104
hash2e320c457658d35a2bb7c420c53bdcc3916f01a7dd4572e5540e8fce923d201b
hash2e81945ba27108cc613a8aa6aca409ad6f5204e647d08dd9ef7c881c9d28667a
hash38f0e1e00d5c6d4afd96217556ba1dbe963298be4f9f0890fc1a7618bed009bd
hash5f2a06bb1d1a210e9c477e4e5db439ce7b11fe9345d39b1b959905ba576a076a
hash74456a8d6042a4232071bee99e25d23046b993486d6d8a98ab296915bbb53395
hash7d8e98c0e322110021ae6d89f1a3ea090ef0741cf35b040dd4d0426a502d4845
hash877648c6ff448aa4efe1e3f004c089411285b8cb4139320e0dbec9d1d1bb3c77
hash87c15e4cf30098dcbfe9fd506c42896bf6d856aa77a70f312dd621b443b61dc3
hash8f18e02cbe1fa7abd280d2e070efe7af07e20cfe635f81140d6d347c292f8f44
hash9c02d5429717001c55420730ee345c172e7ed89df3052b1e32b9bd122fce616d
hashaebf896b2f60c52af5d38c036159e0243632134643e8ad374cb64ed8cb09f360
hashb1d037e9ff070d9722b7b289629d9b64a08ec35fd843cc01d37e6db69781ddcb
hashb8a1494b68617de92a3f58af8ca49dda4e9894f24c718ff3b26897a340e45c80
hashbfc008f57dca8c6bf341d9d7cf66cdad53faf8b1bcfbeded4593a60f129174b6
hashc2c9187033d22d7944ea9298461a0ac693ef2774b4ce08b0955d2aba3646fb44
hashc6db004f2e8ff321d8a0e6d0134f2737d0f6ff79a4627a4b803ef926c107aa00
hashf611e5415e21f229f75a42011d092e781ffe4118bb70ac95b9d85c41c81ef6ca

Threat ID: 6a914fc1acd9273b49a91700

Added to database: 08/28/2026, 09:07:13 UTC

Last updated: 08/28/2026, 16:03:23 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses