HOOKEDGE backdoor deployment via macro-enabled Word documents
Malware Activity
Summary
Hide ▲
Show ▼
The HOOKEDGE backdoor is being deployed through macro-enabled Microsoft Word documents, giving attackers a lightweight Windows batch foothold for remote command execution and data exfiltration. The payload uses webhook[.]site for command-and-control, staging, and exfiltration, which helps the traffic blend into normal web activity. The activity has been observed against government and diplomatic organizations in Romania, Spain, and Türkiye during late September 2025 to early April 2026.
Related Happenings
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
Campaign
H score24
First: 19.07.2026 16:30
Last: 19.07.2026 16:30
Sources 1
About this happening:
A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
CampaignAbout this happening: A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...
Webworm EchoCreep and GraphWorm backdoor expansion
Malware Activity
H score28
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm expanded its malware arsenal in 2025 with the custom backdoors EchoCreep and GraphWorm, increasing its ability to run stealthy command-and-control oper...
Webworm EchoCreep and GraphWorm backdoor expansion
Malware ActivityAbout this happening: Webworm expanded its malware arsenal in 2025 with the custom backdoors EchoCreep and GraphWorm, increasing its ability to run stealthy command-and-control oper...
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
BadPaw multi-stage backdoor deployment targeting Ukraine
Malware Activity
H score22
First: 04.03.2026 16:30
Last: 04.03.2026 16:30
Sources 1
About this happening:
Researchers uncovered BadPaw, a multi-stage malware operation that uses ukr[.]net-hosted email lures and staged redirects to install a backdoor on Ukrainian target...
BadPaw multi-stage backdoor deployment targeting Ukraine
Malware ActivityAbout this happening: Researchers uncovered BadPaw, a multi-stage malware operation that uses ukr[.]net-hosted email lures and staged redirects to install a backdoor on Ukrainian target...
Webhook-based macro malware chain
Malware Activity
H score19
First: 23.02.2026 21:41
Last: 23.02.2026 21:41
Sources 1
How related:
HOOKEDGE's primary delivery vehicle is a macro-enabled Microsoft Word document that, when opened, prompts the target to click "Enable Content" to display the contents, causing the macro routing to write six files to the "%userprofile%" directory and launch the HOOKEDGE installer chain.
About this happening:
APT28 (BlueDelta) ran HOOKEDGE campaigns against government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early Apr...
Webhook-based macro malware chain
Malware ActivityHow related: HOOKEDGE's primary delivery vehicle is a macro-enabled Microsoft Word document that, when opened, prompts the target to click "Enable Content" to display the contents, causing the macro routing to write six files to the "%userprofile%" directory and launch the HOOKEDGE installer chain.
About this happening: APT28 (BlueDelta) ran HOOKEDGE campaigns against government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early Apr...
Latest development: 28.08.2026 11:20
APT28, tracked as BlueDelta, ran HOOKEDGE campaigns against government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early April 2026, using macro-enabled Microsoft Word lures, webhook[.]site for command-and-control, payload staging, and data exfiltration, and Microsoft Edge in headless or hidden mode to fetch commands and return output. The activity overlaps HEADLACE tradecraft and includes second-stage webhook endpoints for higher-value targets.
Timeline
-
28.08.2026 11:20 2 articles · 2h ago
HOOKEDGE backdoor deployment via macro-enabled Word documents
Initial DisclosureThe first stage relies on a macro-enabled Microsoft Word document that prompts the victim to Enable Content and launch the HOOKEDGE installer chain. Early activity focused on broad initial access before later refinements shifted higher-value victims to tighter operator control.
Show sources
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations — thehackernews.com — 28.08.2026 11:20
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations — thehackernews.com — 28.08.2026 11:20