BoletimSecAugust 31, 2026🇵🇹Translated from Portuguese

APT28 Expands Espionage with New HOOKEDGE Backdoor Targeting European Organizations

The Russian military intelligence-linked group APT28, also tracked as BlueDelta, has expanded its espionage operations with a new backdoor called HOOKEDGE aimed at Windows systems.

The campaign, assessed with moderate confidence, focused on government, diplomatic, and defense-sector organizations in Romania, Spain, and Turkey. Attacks occurred between September 2025 and April 2026.

Initial access relied on spear-phishing emails containing Microsoft Word documents with macros. Some files impersonated Spanish government materials and prompted victims to click “Enable Content.”

Execution of the macro writes files to the user directory, launches an installation chain, and creates a scheduled task for persistence. Several installation components are deleted afterward to hinder forensic analysis.

HOOKEDGE is a lightweight backdoor written in batch scripts. It polls external servers for commands, executes .cmd files on the compromised host, and returns results to the operators.

To evade detection, the malware routes traffic through hidden or headless instances of Microsoft Edge and the legitimate webhook.site service, making malicious communications resemble ordinary web browsing.

Against higher-value targets, operators deployed a second HOOKEDGE instance configured for five-minute check-ins, enabling faster command execution and data exfiltration.

The new implant shares significant code similarities with the older HEADLACE backdoor previously linked to the same threat actor.

Related articles

BoletimSecState-Sponsored & APT

US Offers $10 Million Reward for Iranian IRGC Cyber Commander Amir Yaryab

The United States has announced a reward of up to $10 million through the Rewards for Justice program for information leading to the identification or location of Amir Yaryab, leader of the Cyber Operations Command within Iran's Islamic Revolutionary Guard Corps (IRGC). Yaryab oversees units responsible for cyber operations targeting critical infrastructure across the United States, Europe, and the Middle East. Groups under his direction, including Shahid Hemmat and Shahid Shushtari, have conducted campaigns against defense, energy, telecommunications, finance, transportation, hotels, and airlines sectors. He is also linked to structures associated with the CyberAv3ngers group, known for attacks on industrial control systems and operational technology equipment. Previous operations attributed to IRGC-linked actors compromised internet-exposed Unitronics programmable logic controllers, affecting at least 75 devices between November 2023 and January 2024, including 34 in the US water and wastewater sector. The reward specifically targets individuals acting under foreign government direction in malicious cyber activities against US critical infrastructure.

BoletimSecState-Sponsored & APT

Iran-Linked Cyber Attack Leaves Small UK Power Plant Offline for Four Days

A cyber attack attributed to hackers with suspected ties to Iran took a small-scale UK power generation facility offline for approximately four days in July 2026. The incident affected a roughly 15 MW generator used to support peak demand periods, yet caused no customer outages or disruption to the national electricity grid. British authorities have not issued an official attribution, and investigators have not publicly identified the malware, vulnerability, or initial access vector used in the operation. Recovery required four days of extensive validation across controllers, configurations, security systems, and remote access points to ensure no residual risks remained. The case highlights the operational challenges of restoring industrial control environments after suspected nation-state activity. In response, UK authorities have strengthened guidance for the energy sector and are considering additional protective measures for critical infrastructure suppliers.

BoletimSecState-Sponsored & APT

Iran-Linked Tortoiseshell Group Deploys Malicious wtsapi32.dll Backdoor for Persistent Windows Access

Researchers have uncovered new tools deployed by the Tortoiseshell group, an Iranian-linked threat actor also tracked as Mirage Kitten, UNC1549, and Nimbus Manticore. The campaign features a Windows backdoor disguised as the legitimate wtsapi32.dll library that silently establishes reverse SSH tunnels over port 443 to maintain access to compromised networks. Active since at least 2018, the group has targeted defense, aerospace, technology, IT services, and military organizations primarily in the Middle East and the United States. The malware preserves expected Windows API functions while enabling command execution, file exfiltration, in-memory DLL loading, directory listing, and system reconnaissance. Associated infrastructure spans the United Arab Emirates, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia, and Japan.

AntiMalwareState-Sponsored & APT

HoneyMyte APT Deploys Kernel-Level CoolClient Backdoor Disguised as Microsoft Defender

The Chinese-speaking APT group HoneyMyte has deployed an updated version of its CoolClient backdoor in espionage operations targeting government and private organizations in Russia, Myanmar, Mongolia, Pakistan, and India. The new variant operates at the Windows kernel level using a signed driver, allowing it to hide processes, files, registry entries, and network activity while evading detection. Attackers first abuse PlugX to add exclusions for Microsoft Defender, then drop a fake Windows Defender directory containing the renamed Sangfor binary defender.exe and the malicious libngs.dll. A scheduled task ensures persistence by launching the fake defender.exe with high privileges on system startup. Kaspersky GReAT researchers note that the kernel-mode capabilities significantly increase the backdoor’s stealth and survivability compared to its previous user-mode implementation. The campaign demonstrates sophisticated living-off-the-land techniques combined with legitimate software abuse.