APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Summary

Cybersecurity researchers have identified new campaigns targeting European government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns have resulted in the deployment of a new backdoor named HOOKEDGE, which is a lightweight Windows batch script.

IFF Assessment

FOE

The discovery of a new backdoor being used in targeted campaigns against government organizations represents a threat to defenders.

Defender Context

This discovery highlights the ongoing threat posed by sophisticated actors like APT28 to sensitive government and diplomatic entities. Defenders should be aware of the HOOKEDGE backdoor and monitor for its potential deployment, especially in regions and sectors targeted by these campaigns. Incident response teams should be prepared to detect and remediate this specific type of threat.

Read Full Story →