APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Executive Summary

Cybersecurity researchers identified a series of campaigns from late September 2025 to early April 2026 that targeted government and diplomatic entities in Romania, Spain, and Türkiye. The attacks deployed a previously undocumented backdoor called HOOKEDGE, a lightweight Windows batch script that was distributed via compromised or malicious channels. The campaigns were attributed to APT28 and highlighted the group’s continued focus on European state actors.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-28T08:20:59+00:00 - Category: threat-intel

Original Description: Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via

"It is the mark of an educated mind to be able to entertain a thought without accepting it."

— Aristotle
Source: The Hacker News