Russian APT28 spies on European governments with HOOKEDGE
Researchers say a Russian state-linked hacking group used a backdoor called HOOKEDGE to spy on government, diplomatic, and defense-related organizations in Romania, Spain, and Turkey. The group, tracked as BlueDelta and widely known as APT28 or Fancy Bear, hid its spying traffic by routing it through Microsoft Edge and a legitimate developer testing service called webhook.site. The campaign is reported to have run from late September 2025 through early April 2026 and has since ended.
- Started
- Sep 25, 2025
- Latest activity
- Apr 1, 2026
- Attributed to
- BlueDelta (APT28 / Fancy Bear)Likely
- Where
- Romania, Spain, Turkey
- Sectors
- Government, Defence
Current status
Recorded Future and other researchers, publishing in late August and early September 2026, describe the campaign as having run from September 2025 to April 2026 with no newer confirmed activity reported.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Recorded Future's Insikt Group attributes the campaign to BlueDelta, which it says overlaps with APT28, with moderate confidence; no government has confirmed it.
Impact
Government, diplomatic, and defense-related organizations in three European countries had a spying backdoor placed on their networks that let attackers quietly send and receive data disguised as normal browser traffic.
What to do
Network defenders at government and defense organizations in the affected countries should watch for the indicators published by Recorded Future and check for HOOKEDGE-related traffic to webhook.site.
Timeline
-
Sep 5, 2026
Additional reporting citing PolySwarm confirmed the same HOOKEDGE campaign details and targeting.
Dormantgbhackers.com -
Aug 12, 2026
Recorded Future's Insikt Group published research attributing the HOOKEDGE backdoor campaign against Romania, Spain, and Turkey to BlueDelta, a cluster overlapping with APT28.
Dormantsecurityaffairs.com
Sources
- Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations SecurityAffairs Aug 12, 2026
- Russian attackers use HOOKEDGE spyware in Europe GBHackers Sep 5, 2026
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations The Hacker News Aug 28, 2026