APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Recorded Future links APT28 to a newly documented HOOKEDGE backdoor deployed against diplomatic and government targets in Romania, Spain, and Türkiye—escalating the direct threat to EU institutions.
Summary written by editorial AI · Source link below
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.
These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via
Editorial Analysis
State-sponsored campaigns directly targeting European government infrastructure demand immediate defensive action from any organisation in the EU diplomatic or public-sector supply chain.
Prioritise HOOKEDGE IOC deployment, review email-security controls for spear-phishing resilience, and alert government-sector partners.
Russian APT28 is deploying a new backdoor against European government entities—direct risk to EU-facing organisations.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d