Recordedfuture
BlueDelta Espionage Campaign Using HOOKEDGE Targets European Governments
Article Content
BlueDelta, a Russian state-linked threat actor, has conducted a series of espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early April 2026. The campaigns utilized a lightweight Windows backdoor named HOOKEDGE, delivered through macro-enabled Microsoft Word documents that impersonated legitimate diplomatic communications. The backdoor exploits legitimate webhook services for command-and-control operations, allowing it to blend in with normal network traffic. The attacks are characterized by continuous refinement of the HOOKEDGE implant to evade detection and adapt to changes in defensive measures. BlueDelta has a history of targeting defense and policy-related organizations, reinforcing its focus on intelligence collection against European entities. Organizations are advised to block macro execution from internet-originated documents and enhance detection capabilities for specific behaviors associated with the malware. The current status indicates ongoing activity from BlueDelta with no signs of cessation.
Key Points: • BlueDelta targets government and diplomatic sectors in Romania, Spain, and Türkiye. • HOOKEDGE backdoor is delivered via macro-enabled Word documents using legitimate lures. • Organizations should block macros from internet documents and enhance detection measures.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.