Executive Summary
Insikt Group has identified a series of campaigns by the Russian state-sponsored group BlueDelta (overlapping with APT28/Fancy Bear) targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late 2025 and early 2026. The group utilized a lightweight Windows batch-script backdoor named HOOKEDGE, delivered via diplomatic-themed lures, including documents impersonating the Spanish Ministry of Justice. This activity appears aimed at collecting intelligence relevant to Russian interests, specifically concerning Moldovan political affairs and NATO governance.
Technically, HOOKEDGE represents an evolution of the group's HEADLACE malware, relying heavily on Legitimate Internet Services (LIS) for operational infrastructure. The malware abuses webhook[.]site for command-and-control (C2), payload staging, and data exfiltration, effectively blending with legitimate HTTPS traffic. BlueDelta demonstrated operational maturity by implementing tiered tasking, using initial infections to triage high-value targets for more intensive monitoring via secondary payloads with shorter beaconing intervals.
The impact is significant for European defense and diplomatic sectors, as BlueDelta continues to refine its initial access tradecraft to evade sandbox detection—such as extending beaconing intervals beyond common 60-minute monitoring windows. Organizations should prioritize hardening macro policies and monitoring for suspicious browser automation and outbound webhook communication.
