A newly identified Windows backdoor abuses Microsoft Edge and webhook.site infrastructure to spy on defense and diplomatic targets across Romania, Spain, and Türkiye.

Intelligence Lead

Security researchers have confirmed a renewed espionage campaign by the Russian GRU-linked threat actor tracked as APT28 (Fancy Bear, Forest Blizzard, BlueDelta), deploying a lightweight backdoor designated HOOKEDGE against defense manufacturers, government ministries, and diplomatic missions in Romania, Spain, and Türkiye. The operation, active from late September 2025 through early April 2026, relied on legitimate webhook infrastructure to mask command-and-control traffic as routine web activity, complicating detection across three NATO member states positioned along Europe's eastern and southern flanks.

Situation Report

Threat intelligence researchers assess that HOOKEDGE entered target networks through macro-enabled Microsoft Word documents delivered via spearphishing. Once executed, the backdoor launches a hidden or headless instance of Microsoft Edge to poll a staging URL hosted on webhook.site, a legitimate service used by developers for testing HTTP callbacks. Retrieved commands are executed locally as batch scripts, with output relayed back through the same webhook channel disguised as an HTML file upload.

Confirmed targets span defense-industrial manufacturers, government ministries, and diplomatic missions, with the geographic concentration in Romania, Spain, and Türkiye read by analysts as consistent with a Russian intelligence interest in NATO's eastern and southern approaches, alliance logistics corridors, and Black Sea security posture. No named individual victims have been publicly disclosed, and the campaign is described by researchers as narrow and target-specific rather than broad and opportunistic.

Attribution to APT28, the threat cluster linked to Unit 26165 of Russia's GRU military intelligence directorate, is assessed with moderate confidence, based on infrastructure and tradecraft overlaps rather than direct forensic confirmation.

Background & Context

APT28 has operated as one of the most persistent state-sponsored intrusion sets targeting European governments, defense contractors, and political institutions for more than a decade, with prior campaigns implicated in interference operations, credential-harvesting against NATO-adjacent ministries, and sustained targeting of Ukraine-related diplomatic channels since 2022. Researchers have identified significant code and tradecraft overlap between HOOKEDGE and HEADLACE, a modular backdoor the same actor has used against diplomatic targets since April 2023, indicating iterative tool development rather than a wholesale change in methodology.

The use of webhook.site and similar developer-facing services for command-and-control is a recognisable evolution in Russian state tradecraft, allowing operators to avoid the cost and forensic exposure of dedicated infrastructure while blending malicious traffic into volumes of legitimate HTTP requests that most network defenses do not flag by default.

Analysis & Assessment

The targeting pattern across Romania, Spain, and Türkiye suggests an intelligence requirement centred on NATO's flank states rather than core Western European capitals, consistent with Moscow's sustained interest in alliance posture along the Black Sea and Mediterranean theatres amid the ongoing war in Ukraine. The choice of legitimate infrastructure for command-and-control is likely to be replicated by other state and criminal operators, given its low cost and demonstrated evasion value, and defenders should anticipate similar abuse of webhook aggregators, paste services, and cloud collaboration platforms in unrelated campaigns.

Continued reliance on macro-enabled document lures indicates that despite years of vendor mitigation efforts, spearphishing against defense and diplomatic personnel remains a reliably effective initial access vector. The moderate-confidence attribution leaves open the possibility of a closely affiliated GRU-adjacent contractor rather than a core APT28 operating cell, a distinction with limited operational consequence for network defenders but relevant for policymakers weighing response options.