Threat Intelligence

New HOOKEDGE Backdoor Linked to Russian State Hackers Hits European Governments

The Hacker News · 28 Aug 2026
Key Takeaway Even if you're not a government target, keep systems patched and monitor for unusual script activity, as tools developed for state-level espionage can eventually filter down to attacks on smaller businesses.

Researchers at Recorded Future's Insikt Group have identified a fresh cyber-espionage campaign targeting government and diplomatic organizations in Romania, Spain, and Türkiye, running from late September 2025 through early April 2026. The campaign deploys a previously undocumented backdoor named HOOKEDGE, described as a lightweight Windows batch script used to gain persistent access to compromised systems.

The activity has been linked to APT28, a threat actor group widely attributed to Russian state interests and known for long-running espionage operations against Western governments, militaries, and diplomatic institutions. While the technical details of the delivery method are still emerging, the use of a simple batch script highlights how attackers continue to favour lightweight, hard-to-detect tools that can blend into normal system activity.

Although this campaign currently targets government and diplomatic entities in Europe, Australian small and medium businesses should take note. State-linked threat groups often refine tools like HOOKEDGE before repurposing them, or selling variants, for broader use against private sector supply chains, including smaller organisations connected to government contracts or international partners.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.