BlueDelta (APT28) deployed a lightweight Windows batch-script backdoor called HOOKEDGE against European government and diplomatic targets between September 2025 and April 2026. HOOKEDGE abuses webhook.site for C2, payload staging, and exfiltration, using Microsoft Edge as its HTTP client to blend with legitimate browsing traffic. The backdoor is a direct evolution of the HEADLACE implant, retaining batch-based execution, GUID-named file artifacts, and legitimate internet service abuse while introducing tiered beaconing to manage webhook.site free-tier request limits.
HOOKEDGE
1 post
BlueDelta Targets Defense and Diplomacy with HOOKEDGE