HOOKEDGE is a lightweight Windows batch-script backdoor used in cyberespionage campaigns targeting government, diplomatic, and defense-manufacturing organizations in Romania, Spain, and Türkiye. It shares substantial code, architectural, and tradecraft characteristics with HEADLACE and has been associated with BlueDelta, the Russian GRU-linked threat activity also tracked as APT28, Fancy Bear, and Forest Blizzard.
HOOKEDGE is delivered through macro-enabled Microsoft Word documents distributed as spearphishing attachments. The documents use diplomatic themes or generic prompts encouraging recipients to enable macros. Macro execution launches a script-based installation chain that establishes persistence through Windows scheduled tasks and deletes installation artifacts.
The backdoor periodically polls a legitimate public webhook service for attacker-supplied command payloads. It uses headless or hidden Microsoft Edge instances to retrieve payload fragments, reconstructs and executes command scripts, and captures their output. Results are embedded in an HTML document and submitted through an HTTP POST request to a separate webhook endpoint. Browser-mediated communications and legitimate-service abuse help its traffic blend with ordinary web activity. The backdoor also removes temporary files and residual download artifacts after execution.
Observed configurations use different polling intervals, including 30-minute and 61-minute first-stage schedules. Selected victims received additional HOOKEDGE instances with separate endpoints and polling intervals as short as five minutes, enabling more responsive operator tasking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaigns delivered a lightweight Windows batch-script backdoor, dubbed "HOOKEDGE," via macro-enabled Microsoft Word documents using diplomatic-themed lures.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
It creates a scheduled task that runs every 30 minutes, launching the HOOKEDGE launcher with the HOOKEDGE payload as its argument.
“the document’s AutoOpen routine writes batch, command, VBScript, HTML, and XHTML files into the user’s profile directory. These components start a multi-stage installer.”
HOOKEDGE is a lightweight Windows batch backdoor that enables remote command execution by retrieving arbitrary .cmd payloads from a staging webhook.
“The group adjusted its methods during the observed period, including changing lures, obscuring VBA code.”
The second-stage payloads retrieved by HOOKEDGE share JavaScript code ... using identical variable names, properties, structure, and base64 encoding schemes for automated file downloads.
“a fake Word error message tries to make the suspicious behavior seem routine.”
The installer then deletes itself, the installer launcher, and the task definition file, removing the primary installation artifacts.
Defense Evasion: Deobfuscate/Decode Files or Information — T1140.
Outbound connections from infected hosts are directed to a legitimate HTTPS service, with a web browser serving as the HTTP client.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight batch-script backdoor delivered through macro-enabled Word documents. It uses legitimate webhook services for command-and-control, payload staging, and data exfiltration, blending malicious activity into legitimate web traffic.
A Windows espionage backdoor delivered through spearphishing macro-enabled Word documents. It establishes scheduled-task persistence, periodically retrieves commands through Microsoft Edge from webhook-based staging infrastructure, executes the commands, and exfiltrates their output through a separate endpoint while deleting temporary artifacts.
A Windows polling backdoor delivered through spearphishing macro-enabled Word documents. It establishes scheduled-task persistence, uses hidden Microsoft Edge instances to retrieve commands and exfiltrate command output via a public webhook service, and removes temporary installation and download artifacts.
A Windows polling backdoor delivered through macro-enabled Word documents. It establishes scheduled-task persistence, uses Microsoft Edge to retrieve commands from webhook.site, executes concatenated .cmd payloads, captures command output, and exfiltrates it through separate webhook endpoints. Higher-priority victims can receive a second instance with more frequent beaconing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.