Recorded Future reports a real espionage campaign attributed to Russia-linked BlueDelta/APT28 targeting European government and diplomatic organizations. Attackers used diplomatic-themed, macro-enabled Word documents (including content impersonating Spain’s Ministry of the Presidency) to trick recipients into running a lightweight backdoor (HOOKEDGE) that blended its internet traffic into normal Microsoft Edge browsing.
Key findings
- Campaign ran from late September 2025 through early April 2026 and targeted government and diplomatic organizations in Romania, Spain, and Türkiye.
- Initial access used macro-enabled Microsoft Word documents with diplomatic-themed lures, including material impersonating Spain’s Ministry of the Presidency.
- The lure documents included tracking “canary” images (e.g., docopened.jpg and mailopened.jpg) to tell operators when an email or document was opened.
- Once a victim appeared high-value, operators deployed a second HOOKEDGE payload with faster check-ins (every five minutes) for more interactive control.
- HOOKEDGE used Microsoft Edge (msedge.exe) to blend command-and-control and data exfiltration traffic into normal browsing activity.
Who’s being targeted
- Commonly targeted roles: Government and public sector staff, Diplomats / foreign affairs staff, Executive assistants, Policy and international relations teams.
- Affected industries: Government, Diplomatic/Foreign Affairs.
- Attack channels: email.
- Impersonated: Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, Sender of a diplomatic/government document (implied government/diplomatic context).
Awareness takeaways
- Treat “diplomatic” or current-events-themed attachments as high risk, verify unexpected meeting documents through a known, separate channel before opening.
- Do not enable macros in documents received from email or downloaded from the internet unless IT/security has explicitly approved it.
- Be aware that simply opening an email or document can trigger “tracking” (remote images) that alerts attackers; avoid loading external content from unexpected senders.
- Report suspicious attachments immediately, this campaign shows attackers can blend in by using normal tools like Microsoft Edge, so early human reporting still matters.
Red flags to watch for
- Unexpected macro-enabled Word attachment tied to current events
- Pressure/credibility created by real-world timing (immediately after an actual meeting)
- Document requires enabling macros to view/activate content
- Document contains hidden remote content that phones home when opened
- Unusual outbound web requests to webhook services from office documents
- Tracking behavior that occurs before any legitimate business interaction
Read the video transcript
You get an email: “Agenda – Spain’s Ministry of the Presidency, post‑meeting notes.” Looks legit, right after a real summit. The attached Word file opens a diplomatic-looking agenda, impersonating Spain’s Ministry. It tells you: “Enable macros to view full content.” That click quietly drops a HOOKEDGE backdoor and even pings a hidden image like docopened.jpg so they know you opened it. From there, HOOKEDGE hides inside normal browsing, riding along with msedge.exe every few minutes. To you, it’s just Edge. To them, it’s a control channel out of your network. If you get a sudden “official” meeting doc that wants macros, stop and forward it to Security, don’t enable anything until they clear it.