APT28 Lures Diplomats with Fake Ministry Docs

Security Affairs · High sophistication
Last updated August 28, 2026

Recorded Future reports a real espionage campaign attributed to Russia-linked BlueDelta/APT28 targeting European government and diplomatic organizations. Attackers used diplomatic-themed, macro-enabled Word documents (including content impersonating Spain’s Ministry of the Presidency) to trick recipients into running a lightweight backdoor (HOOKEDGE) that blended its internet traffic into normal Microsoft Edge browsing.

Key findings

  • Campaign ran from late September 2025 through early April 2026 and targeted government and diplomatic organizations in Romania, Spain, and Türkiye.
  • Initial access used macro-enabled Microsoft Word documents with diplomatic-themed lures, including material impersonating Spain’s Ministry of the Presidency.
  • The lure documents included tracking “canary” images (e.g., docopened.jpg and mailopened.jpg) to tell operators when an email or document was opened.
  • Once a victim appeared high-value, operators deployed a second HOOKEDGE payload with faster check-ins (every five minutes) for more interactive control.
  • HOOKEDGE used Microsoft Edge (msedge.exe) to blend command-and-control and data exfiltration traffic into normal browsing activity.

Who’s being targeted

  • Commonly targeted roles: Government and public sector staff, Diplomats / foreign affairs staff, Executive assistants, Policy and international relations teams.
  • Affected industries: Government, Diplomatic/Foreign Affairs.
  • Attack channels: email.
  • Impersonated: Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, Sender of a diplomatic/government document (implied government/diplomatic context).

Awareness takeaways

  • Treat “diplomatic” or current-events-themed attachments as high risk, verify unexpected meeting documents through a known, separate channel before opening.
  • Do not enable macros in documents received from email or downloaded from the internet unless IT/security has explicitly approved it.
  • Be aware that simply opening an email or document can trigger “tracking” (remote images) that alerts attackers; avoid loading external content from unexpected senders.
  • Report suspicious attachments immediately, this campaign shows attackers can blend in by using normal tools like Microsoft Edge, so early human reporting still matters.

Red flags to watch for

  • Unexpected macro-enabled Word attachment tied to current events
  • Pressure/credibility created by real-world timing (immediately after an actual meeting)
  • Document requires enabling macros to view/activate content
  • Document contains hidden remote content that phones home when opened
  • Unusual outbound web requests to webhook services from office documents
  • Tracking behavior that occurs before any legitimate business interaction
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Agenda – Spain’s Ministry of the Presidency, post‑meeting notes.” Looks legit, right after a real summit. The attached Word file opens a diplomatic-looking agenda, impersonating Spain’s Ministry. It tells you: “Enable macros to view full content.” That click quietly drops a HOOKEDGE backdoor and even pings a hidden image like docopened.jpg so they know you opened it. From there, HOOKEDGE hides inside normal browsing, riding along with msedge.exe every few minutes. To you, it’s just Edge. To them, it’s a control channel out of your network. If you get a sudden “official” meeting doc that wants macros, stop and forward it to Security, don’t enable anything until they clear it.

Categories

Similar attacks

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
SilkParasite Hits Central Asia via Phish Docs

SilkParasite Hits Central Asia via Phish Docs

Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel…

August 20, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026