APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

The Hacker News · High sophistication
Last updated August 28, 2026

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based command-and-control infrastructure.

Key findings

  • Campaigns targeted government and diplomatic organizations in Romania, Spain, and Türkiye (late Sept 2025 to early April 2026).
  • Initial access relied on macro-enabled Word documents with diplomatic-themed lures and an “Enable Content” prompt.
  • Early lures impersonated Spanish government material, then shifted to a more explicit social-engineering approach.
  • A hidden image in the lure document referenced a webhook[.]site URL to alert operators when the document was opened.
  • HOOKEDGE used scheduled tasks for persistence and leveraged webhook[.]site for payload staging and data exfiltration to blend with normal web traffic.
  • A second-stage payload with more frequent beaconing (as little as five minutes) was used for high-value targets.

Who’s being targeted

  • Commonly targeted roles: Government employees, Diplomatic/foreign affairs staff, Executive assistants, Senior leadership, Security operations / IT.
  • Affected industries: Government, Diplomatic / Foreign Affairs, Public Sector.
  • Attack channels: email.
  • Impersonated: Spanish government (official material), Diplomatic organization / government sender.

Awareness takeaways

  • Treat any Office document asking you to click “Enable Content” as suspicious, stop and report it.
  • Be cautious with “official” diplomatic/government-themed documents, attackers can impersonate trusted institutions.
  • Opening a document can trigger silent tracking and external connections; report unexpected prompts or unusual behavior after opening attachments.
  • Disable or block macros from internet-sourced documents wherever possible to reduce risk from document-based attacks.

Red flags to watch for

  • Attachment is a macro-enabled Microsoft Word document
  • Document asks the user to click “Enable Content” to view content
  • Diplomatic/government theme used to create urgency and credibility
  • Unexpected external network activity immediately upon opening a document
  • Document contains embedded/hidden elements (e.g., images) that fetch remote content
  • Unsolicited diplomatic-themed attachments from unfamiliar or unusual senders
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Diplomatic briefing document (requires Enable Content)” with an official-looking Word file attached. This is how APT28 has been hitting ministries in Romania, Spain, and Türkiye: a macro-enabled Word doc that opens, phones home via a hidden image to webhook.site, then pushes the HOOKEDGE backdoor. The trick is simple: the document impersonates Spanish government or diplomatic material and shoves a big yellow bar telling you to click “Enable Content” so you can read it. That click lets the HOOKEDGE malware in. Your move is easy: if any Office document asks you to click “Enable Content,” especially for diplomatic or government material, stop and report it to security, do not click.

Categories

Similar attacks

Korea APTs Push LNK “Resume” Spear‑Phish

Korea APTs Push LNK “Resume” Spear‑Phish

AhnLab reports that many APT attacks targeting organizations in South Korea in July 2026 started with spear‑phishing emails that delivered malicious Windows shortcut (LNK) files disguised as legitimate documents (including resumes). When opened, the LNK runs scripts that install…

August 28, 2026
APT28 Lures Diplomats with Fake Ministry Docs

APT28 Lures Diplomats with Fake Ministry Docs

Recorded Future reports a real espionage campaign attributed to Russia-linked BlueDelta/APT28 targeting European government and diplomatic organizations. Attackers used diplomatic-themed, macro-enabled Word documents (including content impersonating Spain’s Ministry of the Presidency) to trick…

August 28, 2026
SilkParasite Hits Central Asia via Phish Docs

SilkParasite Hits Central Asia via Phish Docs

Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel…

August 20, 2026
Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026