Fortinet has a security flaw
Russian government attackers known as APT28 sent fake Word documents to defense companies, government offices, and embassies in Romania, Spain, and Turkiye. Opening the file and enabling macros installed a spying tool called HOOKEDGE that let the attackers run commands and pull data off the victim's computer.
- Report priority
- Medium
- Targets
- Windows Task Scheduler+2 more
How it works
- Victims receive an email with a Word attachment disguised as an official government document.
- Enabling macros (automated commands built into the file) runs scripts that drop the HOOKEDGE backdoor, make it restart automatically through Windows Task Scheduler, and quietly delete traces of the install.
What to do
This campaign targets specific defense, government, and diplomatic staff in Romania, Spain, and Turkiye, so check whether you or your organization received an unexpected Word document asking you to enable macros or content, and look for scheduled tasks or hidden Edge browser sessions you did not create.
Organizations should block macros in documents downloaded from the internet, restrict unsigned VBA macros, require phishing-resistant multifactor authentication, and review or block unapproved webhook services on the network, per Recorded Future's guidance.
Technical details
Affected software: Windows Task Scheduler, Microsoft Edge, Spain's Ministry of the Presidency
BlueDelta emails a target at a Spanish government office a Word document made to look like it came from Spain's Ministry of the Presidency, Justice and Relations with the Cortes. The recipient opens it and clicks to enable macros, which quietly installs HOOKEDGE and sets it to relaunch on its own. then on the backdoor checks in through a hidden Microsoft Edge browser session and a public webhook service, asking for commands and sending back whatever it collects, so the traffic looks like normal browsing instead of an attack.
HOOKEDGE is a lightweight Windows batch-script backdoor and an evolution of the earlier HEADLACE malware, both sharing batch scripting and browser-based command channels. It checks in through a staging endpoint, rebuilds the returned command into a file, executes it, and reports results to a separate endpoint, all routed through hidden Microsoft Edge sessions and a public webhook service rather than an attacker-owned server. Recorded Future's Insikt Group observed a first-stage check-in interval extended to 61 minutes, likely to outlast automated sandboxes, with a faster 5-minute variant deployed against higher-value victims instead of the usual 30-minute interval. The group refined lures, browser settings, and timing between September 2025 and April 2026.
References
- ppl-ai-file-upload.s3.amazonaws.com · Russian-Hackers-Use-New-HOOKEDGE-Malware-to-Spy-on-European-Defense-and-Diplomatic-Targets.pdf Cyber Security News
- recordedfuture.com · bluedelta-targets-with-hookedge Cyber Security News
- any.run · threat-intelligence-lookup Cyber Security News
- thehackernews.com · newly-sleepwalker-backdoor-waits-for.html TheHackerNews
- infosecurity-magazine.com · gunra-ransomware-fortinet-flaws Infosecurity Magazine
- thehackernews.com · whatsapp-adds-multiple-passkeys-for.html TheHackerNews
- thehackernews.com · novacookies-campaigns-abuse-genuine.html TheHackerNews
- thehackernews.com · terminalfix-uses-fake-cloudflare.html TheHackerNews
- thehackernews.com · 24-npm-packages-abuse-unpkg-mirrors-to.html TheHackerNews