BlueDelta Espionage Campaign Using HOOKEDGE Targets European Governments

BlueDelta Espionage Campaign Using HOOKEDGE Targets European Governments

First seen 28 Aug 2026, 11:21 UTC RecordedfutureGbhackersSecurityaffairs.Co 72.5

Article Content

Browse articles
ThreatCluster

BlueDelta, a Russian state-linked threat actor, has conducted a series of espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early April 2026. The campaigns utilized a lightweight Windows backdoor named HOOKEDGE, delivered through macro-enabled Microsoft Word documents that impersonated legitimate diplomatic communications. The backdoor exploits legitimate webhook services for command-and-control operations, allowing it to blend in with normal network traffic. The attacks are characterized by continuous refinement of the HOOKEDGE implant to evade detection and adapt to changes in defensive measures. BlueDelta has a history of targeting defense and policy-related organizations, reinforcing its focus on intelligence collection against European entities. Organizations are advised to block macro execution from internet-originated documents and enhance detection capabilities for specific behaviors associated with the malware. The current status indicates ongoing activity from BlueDelta with no signs of cessation.

Key Points: • BlueDelta targets government and diplomatic sectors in Romania, Spain, and Türkiye. • HOOKEDGE backdoor is delivered via macro-enabled Word documents using legitimate lures. • Organizations should block macros from internet documents and enhance detection measures.

Timeline

2025-09-01
BlueDelta campaigns initiated
Initial access campaigns targeting government and diplomatic organizations began in late September 2025.
Recordedfuture
2026-04-01
Campaigns concluded
The identified BlueDelta campaigns targeting European entities ended in early April 2026.
Recordedfuture
2026-08-27
Research published
Recorded Future's Insikt Group published findings on BlueDelta's use of HOOKEDGE malware.
Recordedfuture
2026-08-28
Gbhackers report released
Gbhackers published an article detailing the BlueDelta espionage campaign and its methods.
Gbhackers