CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5296

As cited

Copy frozen at (site build).

threat intel

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Recorded Future Insikt Group identified a backdoor called HOOKEDGE deployed in targeted campaigns against government and diplomatic entities in Romania, Spain, and Türkiye from September 2025 through April 2026. The malware is a lightweight Windows batch script distributed through means not fully detailed in available reporting.

Why it matters: European government and diplomatic staff face active compromise via a novel backdoor; defenders should hunt for HOOKEDGE indicators and review access logs from the campaign window.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Recorded Future Insikt Group identified a backdoor called HOOKEDGE deployed in targeted campaigns against government and diplomatic entities in Romania, Spain, and Türkiye from September 2025 through April 2026. The malware is a lightweight Windows batch script distributed through means not fully detailed in available reporting.

Why it matters: European government and diplomatic staff face active compromise via a novel backdoor; defenders should hunt for HOOKEDGE indicators and review access logs from the campaign window.

VendorsMicrosoft
Actorsapt28
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary