Diplomats in Romania, Spain, and Türkiye have been in the crosshairs of a Russian espionage operation that ran from late September 2025 to early April 2026, according to Recorded Future’s Insikt Group. The researchers linked the campaign with moderate confidence to BlueDelta, the state-sponsored cluster that overlaps with APT28, also known as Fancy Bear and Forest Blizzard.
The delivery mechanism is a lightweight Windows batch script dubbed HOOKEDGE, carried in macro-enabled Word documents dressed up as diplomatic material. Early samples impersonated Spanish government documents before the operators switched tactics a month in. For command-and-control, payload staging, and data exfiltration the implant leans on webhook[.]site, a developer service for testing HTTP requests, so malicious traffic hides inside ordinary web activity and no dedicated infrastructure is needed. Commands arrive on a fixed schedule: a scheduled task wakes every 30 minutes, pulls a command file through Microsoft Edge, runs it, and posts the results to a second endpoint.
Insikt calls HOOKEDGE a direct evolutionary successor to HEADLACE, a modular Windows backdoor APT28 has used against diplomats since April 2023. Core architecture and webhook[.]site abuse match HEADLACE closely, Insikt says. The implant also evolved through the whole campaign, probably to slip past automated sandboxes and adjust to tighter free-tier limits on the service.
For defenders, macro-enabled Word files with diplomatic themes remain a credible APT28 delivery channel, and outbound connections to webhook services deserve scrutiny.
