As cited
Copy frozen at (site build).
threat intel
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Insikt Group identified BlueDelta, a Russian state-sponsored group, conducting campaigns from September 2025 through April 2026 that targeted government and diplomatic organizations in Romania, Spain, and Türkiye using macro-enabled Word documents. The campaigns delivered HOOKEDGE, a lightweight batch-script backdoor that shares code and tradecraft with BlueDelta's earlier HEADLACE malware, and used webhook services for command-and-control to blend malicious activity with legitimate traffic. The group refined the implant repeatedly over those months while targeting European governments on priorities consistent with Russian intelligence collection.
Why it matters: Defense and diplomatic organizations in Europe face direct risk from ongoing BlueDelta campaigns using readily available techniques; practitioners should block macro execution from internet-sourced documents, detect scheduled task abuse and webhook service connections, and monitor for headless browser execution.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Insikt Group identified BlueDelta, a Russian state-sponsored group, conducting campaigns from September 2025 through April 2026 that targeted government and diplomatic organizations in Romania, Spain, and Türkiye using macro-enabled Word documents. The campaigns delivered HOOKEDGE, a lightweight batch-script backdoor that shares code and tradecraft with BlueDelta's earlier HEADLACE malware, and used webhook services for command-and-control to blend malicious activity with legitimate traffic. The group refined the implant repeatedly over those months while targeting European governments on priorities consistent with Russian intelligence collection.
Why it matters: Defense and diplomatic organizations in Europe face direct risk from ongoing BlueDelta campaigns using readily available techniques; practitioners should block macro execution from internet-sourced documents, detect scheduled task abuse and webhook service connections, and monitor for headless browser execution.
- Source published
- First seen by Cybersecurity Tracker