
highThreat Intelligence
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Between late September 2025 and early April 2026, government and diplomatic organizations in Romania, Spain, and Türkiye were targeted in campaigns that deployed HOOKEDGE, a previously undocumented Windows batch script backdoor. Recorded Future Insikt Group attributes the activity to APT28, a likely state-sponsored threat actor. The backdoor's distribution method and initial access vectors remain under investigation, but the campaigns are assessed as espionage-oriented.
The Hacker News1 min read