APT28 Uses Word Lures and Webhooks for HOOKEDGE

Recorded Future says APT28 has used a previously undocumented backdoor called HOOKEDGE against government and diplomatic targets in Romania, Spain, and Türkiye from late September 2025 through early April 2026. The group delivered it through macro-enabled Microsoft Word documents with diplomatic lures, and the campaigns overlap with earlier HEADLACE activity the firm had already tied to APT28. HOOKEDGE is a lightweight Windows batch-script backdoor. When the document is opened and macros are enabled, it drops files, sets a scheduled task, and then pulls commands from webhook[.]site, so its traffic blends into ordinary web activity instead of reaching out to an obvious attacker server. The installer also deletes itself, which reduces forensic residue after execution. The reader takeaway is that the trust boundary is the lure document, not the backdoor binary: if Word documents still get macro trust in your environment, the initial access path can survive even when older implants are blocked. That leaves SOCs watching for Office-macro behavior and webhook traffic in ministries, embassies, and foreign-affairs networks.

Part of the PlainSec briefing for 2026-08-29

Editions

Sources