securityaffairs.com 8/28/2026, 12:29:16 PM · external

BlueDelta APT deploys HOOKEDGE backdoor via malicious Word macros

BlueDelta APT deploys HOOKEDGE backdoor via malicious Word macros
CyberSIXT Evidence Panel
Primary Source recordedfuture.com
Threat Actor

RUSSIAN APT group BlueDelta, linked to the GRU, is targeting European governments using a new backdoor called HOOKEDGE, which operates through macro-enabled Word documents disguised as legitimate government lures. The malware utilizes a combination of scheduled tasks and Microsoft Edge to mask its network activity, making it resemble normal web browsing to evade detection.

BlueDelta's operation reflects a continuous evolution of their tactics, reusing code from previous malware (HEADLACE) and implementing sophisticated tracking to monitor the success of phishing attempts. The report underscores the importance of blocking macro execution and monitoring for unusual scheduled tasks as preventive measures.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline