CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5248

As cited

Copy frozen at (site build).

threat intel

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

Insikt Group identified BlueDelta, a Russian state-sponsored group, conducting campaigns from September 2025 through April 2026 that targeted government and diplomatic organizations in Romania, Spain, and Türkiye using macro-enabled Word documents. The campaigns delivered HOOKEDGE, a lightweight batch-script backdoor that shares code and tradecraft with BlueDelta's earlier HEADLACE malware, and used webhook services for command-and-control to blend malicious activity with legitimate traffic. The group refined the implant repeatedly over those months while targeting European governments on priorities consistent with Russian intelligence collection.

Why it matters: Defense and diplomatic organizations in Europe face direct risk from ongoing BlueDelta campaigns using readily available techniques; practitioners should block macro execution from internet-sourced documents, detect scheduled task abuse and webhook service connections, and monitor for headless browser execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

Insikt Group identified BlueDelta, a Russian state-sponsored group, conducting campaigns from September 2025 through April 2026 that targeted government and diplomatic organizations in Romania, Spain, and Türkiye using macro-enabled Word documents. The campaigns delivered HOOKEDGE, a lightweight batch-script backdoor that shares code and tradecraft with BlueDelta's earlier HEADLACE malware, and used webhook services for command-and-control to blend malicious activity with legitimate traffic. The group refined the implant repeatedly over those months while targeting European governments on priorities consistent with Russian intelligence collection.

Why it matters: Defense and diplomatic organizations in Europe face direct risk from ongoing BlueDelta campaigns using readily available techniques; practitioners should block macro execution from internet-sourced documents, detect scheduled task abuse and webhook service connections, and monitor for headless browser execution.

VendorsMicrosoft
Actorsapt28fancy bearforest blizzard
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary