A wave of cyber‑espionage activity has been traced to the Russian‑linked group APT28, also known as Fancy Bear. Between late September 2025 and early April 2026, the group deployed a new backdoor called „HOOKEDGE” against ministries, embassies, and foreign affairs offices in Romania, Spain, and Türkiye. Researchers at Recorded Future’s Insikt Group first identified the campaigns after noticing a surge of malicious PowerShell scripts and unusual outbound traffic from compromised servers.
The HOOKEDGE implant is a modular backdoor that can download additional payloads, exfiltrate documents, and maintain persistence through scheduled tasks. Analysts say the malware leverages a custom‑crafted Windows loader that evades many endpoint detection products by using legitimate system binaries. The campaign appears to be part of a broader Russian effort to gather diplomatic intelligence ahead of upcoming elections and NATO meetings. „We see a clear pattern of targeting ministries that handle foreign policy and defense,” said Ravie Lakshmanan, a senior threat analyst at Recorded Future. „The timing aligns with key political events in the region, suggesting strategic intent rather than opportunistic hacking.”
HOOKEDGE’s design focuses on stealth. It first drops a small PowerShell script that registers a new scheduled task under a benign name, then uses Windows Management Instrumentation (WMI) to execute the payload without triggering typical alerts. The backdoor also encrypts its command‑and‑control (C2) traffic with a rotating key, making network‑based detection difficult. In one observed case, the malware communicated with a server located in a Russian data center, using a domain that mimics legitimate cloud services. Recorded Future’s telemetry shows that the backdoor has been active on at least 27 compromised hosts, with some remaining undetected for weeks.
The researchers attribute the sophistication of HOOKEDGE to the resources available to APT28, which has a history of targeting government entities across Europe. The group’s previous operations have included the use of the Sofacy and X-Agent families, both of which shared similar persistence mechanisms. By reusing known techniques while adding novel encryption, the attackers increase their chances of evading security tools that rely on signature‑based detection.
The selection of Romania, Spain, and Türkiye reflects the geopolitical interests of the Russian state. All three countries host critical NATO facilities or serve as conduits for intelligence sharing between the alliance and the United States. In Romania, the compromised systems belonged to the Ministry of Foreign Affairs, which coordinates EU diplomatic initiatives. Spain’s targeted entities included the embassy in Washington, D. C., suggesting an attempt to monitor bilateral communications. Türkiye’s foreign ministry, a key player in regional security discussions, also fell victim to the campaign. „These nations are pivotal nodes in the European security architecture,” Lakshmanan noted. „Compromising their diplomatic channels provides a strategic advantage for intelligence gathering.”
The timing of the attacks coincides with the lead‑up to the 2026 NATO summit in Brussels, where member states will discuss defense spending and collective security measures. By infiltrating diplomatic networks, APT28 may be seeking to shape the narrative or pre‑empt policy decisions that could affect Russian interests.
The fallout from the HOOKEDGE campaign could be significant. If sensitive diplomatic communications are exfiltrated, allied nations may face compromised negotiations, delayed policy responses, and a loss of trust in secure channels. Governments are expected to accelerate the rollout of advanced endpoint detection and response (EDR) solutions, as well as to conduct thorough forensic reviews of affected systems. International cooperation on threat intelligence sharing will likely intensify to counter the evolving tactics of state‑backed actors.
What is the HOOKEDGE backdoor? HOOKEDGE is a modular malware family linked to APT28 that establishes a hidden foothold on Windows systems, downloads additional tools, and encrypts its traffic to evade detection.
How did the attackers gain initial access? The group used spear‑phishing emails with malicious attachments, followed by PowerShell scripts that created scheduled tasks and leveraged WMI for silent execution.
What steps can organizations take to protect against similar threats? Implement multi‑layered security, including behavior‑based EDR, strict email filtering, regular patching of Windows components, and continuous monitoring of outbound network traffic for anomalies.