
APT28 HOOKEDGE Backdoor Abuses Microsoft Edge and webhook.site for C2 and Data Exfiltration
Russian state-linked threat actor BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has launched phishing campaigns using a lightweight Windows backdoor called HOOKEDGE. The activity targeted government, diplomatic, and defense manufacturing organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. Insikt Group assessed with moderate confidence that BlueDelta […]
The post APT28 HOOKEDGE Backdoor Abuses Microsoft Edge and webhook.site for C2 and Data Exfiltration appeared first on Cyber Security News.