APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Recorded Future Insikt Group identifies new campaigns using a lightweight Windows batch script backdoor linked to Russian APT28 activity.

Key Takeaways
- APT28-linked campaigns targeted government and diplomatic organizations in Romania, Spain, and Türkiye between late 2025 and early 2026.
- A previously undocumented backdoor, HOOKEDGE, a lightweight Windows batch script, was deployed in these campaigns.
- The distribution method and initial access vectors for HOOKEDGE have not been publicly specified, though spear-phishing and public-facing service exploitation are suspected.
Related Security News

NeedyMantis Malware Used for Long-Term Persistence in Targeted Intrusions
Microsoft has identified a malware family named NeedyMantis being used by threat actors to maintain long-term, unauthorized access to already-breached networks. The malware has been observed in targeted intrusions across a range of sectors, including telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Activity has been tracked since at least 2023 and remains ongoing.




