THREAT OPS › Threat News › BlueDelta Targets Defense and Diplomacy with HOOKEDGE
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
<h2>Executive Summary</h2> <p>Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The campaigns delivered a lightweight Windows batch-script backdoor, dubbed "HOOKEDGE," via macro-enabled Microsoft Word documents using diplomat
Attributed threat actors
- APT28G0007
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
Indicators of compromise
- https://lab52.io/blog/operation-macromaze-new-apt28-campaign-using-basic-tooling-and-legit-infrastructure/url
- webhook.sitedomain