Interestana
Home/News/HOOKEDGE Backdoor Targets European Governments Via APT28
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

HOOKEDGE Backdoor Targets European Governments Via APT28

HOOKEDGE Backdoor Targets European Governments Via APT28

Cybersecurity researchers have identified a new wave of cyberattacks targeting government and diplomatic entities across Romania, Spain, and Türkiye. These campaigns, which took place between late September 2025 and early April 2026, have resulted in the deployment of a previously unknown backdoor named HOOKEDGE. Recorded Future's Insikt Group reported these findings, detailing HOOKEDGE as a lightweight Windows batch script. The threat actor behind these operations is believed to be APT28, also known as Fancy Bear or Strontium, a group with documented ties to Russia's Main Intelligence Directorate (GRU).

The HOOKEDGE backdoor is distributed through sophisticated spear-phishing emails. These emails are crafted to appear legitimate, often impersonating trusted sources or relevant entities to entice recipients into clicking malicious links or opening infected attachments. Once executed, the backdoor establishes a command-and-control (C2) channel, allowing the attackers to remotely manage the compromised systems. The primary objective of these attacks appears to be espionage, aiming to gather sensitive information from the targeted governmental and diplomatic organizations. The use of a batch script for the backdoor suggests a focus on stealth and minimal system footprint, potentially evading detection by standard security software.

Recorded Future's analysis indicates that HOOKEDGE is designed for reconnaissance and initial access, likely serving as a precursor to more advanced stages of compromise. The group's historical activities, attributed to APT28, often involve persistent surveillance, data exfiltration, and disruption of critical infrastructure. The targeting of European government and diplomatic bodies aligns with APT28's long-standing geopolitical objectives. The Insikt Group's report provides technical indicators of compromise (IOCs) and details the observed tactics, techniques, and procedures (TTPs) employed in these campaigns, enabling organizations to enhance their defenses against this emerging threat.

The deployment of HOOKEDGE represents a continued effort by APT28 to infiltrate sensitive networks within NATO-aligned countries. The group's operational tempo has remained high, with previous campaigns documented in late 2024 and early 2025 also focusing on similar targets. The lightweight nature of the HOOKEDGE backdoor may allow it to persist on compromised systems for extended periods without raising immediate alarms. Security professionals are advised to review their network logs for suspicious activity, strengthen their email security gateways, and ensure endpoint detection and response (EDR) solutions are up-to-date to detect and mitigate the threat posed by HOOKEDGE and similar APT28 tools. The ongoing nature of these campaigns underscores the persistent threat posed by state-sponsored cyber actors to national security and diplomatic operations.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next