Russian State Hackers Target European Diplomats with New Backdoor Malware
Security researchers at Insikt Group have uncovered a campaign running from late September 2025 to early April 2026 that targeted government and diplomatic bodies in Romania, Spain and Türkiye. The attackers, known as BlueDelta and linked with moderate confidence to Russian military intelligence (the group also known as APT28 or Fancy Bear), used diplomatic-themed lure documents, including one impersonating Spain's Ministry of the Presidency, to trick recipients into enabling malicious macros in Microsoft Word.
Once activated, the macros deliver a lightweight backdoor named HOOKEDGE. This tool shares its core design with an earlier BlueDelta implant called HEADLACE, and cleverly abuses legitimate webhook services to communicate with its operators and steal data. By hiding its activity inside traffic to trusted services, the malware makes itself harder to spot using normal network monitoring, and it has been steadily refined over several months to dodge automated security scanning.
Rather than building entirely new tools, BlueDelta continues to invest in adapting existing, proven tradecraft to stay ahead of defenders, reflecting a focus on long-term intelligence gathering against European government targets rather than flashy new techniques.