Find notable cyber news and cases, enriched with sources, timelines, and signals.

HOOKEDGE backdoor deployment via macro-enabled Word documents

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The HOOKEDGE backdoor is being deployed through macro-enabled Microsoft Word documents, giving attackers a lightweight Windows batch foothold for remote command execution and data exfiltration. The payload uses webhook[.]site for command-and-control, staging, and exfiltration, which helps the traffic blend into normal web activity. The activity has been observed against government and diplomatic organizations in Romania, Spain, and Türkiye during late September 2025 to early April 2026.

Related Happenings

UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets

Campaign
H score24 First: 19.07.2026 16:30 Last: 19.07.2026 16:30 Sources 1

About this happening: A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...

Webworm EchoCreep and GraphWorm backdoor expansion

Malware Activity
H score28 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm expanded its malware arsenal in 2025 with the custom backdoors EchoCreep and GraphWorm, increasing its ability to run stealthy command-and-control oper...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

BadPaw multi-stage backdoor deployment targeting Ukraine

Malware Activity
H score22 First: 04.03.2026 16:30 Last: 04.03.2026 16:30 Sources 1

About this happening: Researchers uncovered BadPaw, a multi-stage malware operation that uses ukr[.]net-hosted email lures and staged redirects to install a backdoor on Ukrainian target...

Webhook-based macro malware chain

Malware Activity
H score19 First: 23.02.2026 21:41 Last: 23.02.2026 21:41 Sources 1

How related: HOOKEDGE's primary delivery vehicle is a macro-enabled Microsoft Word document that, when opened, prompts the target to click "Enable Content" to display the contents, causing the macro routing to write six files to the "%userprofile%" directory and launch the HOOKEDGE installer chain.

About this happening: APT28 (BlueDelta) ran HOOKEDGE campaigns against government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early Apr...

Latest development: 28.08.2026 11:20

APT28, tracked as BlueDelta, ran HOOKEDGE campaigns against government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early April 2026, using macro-enabled Microsoft Word lures, webhook[.]site for command-and-control, payload staging, and data exfiltration, and Microsoft Edge in headless or hidden mode to fetch commands and return output. The activity overlaps HEADLACE tradecraft and includes second-stage webhook endpoints for higher-value targets.

Timeline

  1. 28.08.2026 11:20 2 articles · 2h ago

    HOOKEDGE backdoor deployment via macro-enabled Word documents

    Initial Disclosure

    The first stage relies on a macro-enabled Microsoft Word document that prompts the victim to Enable Content and launch the HOOKEDGE installer chain. Early activity focused on broad initial access before later refinements shifted higher-value victims to tighter operator control.

    Show sources