SecurityIndependently confirmed3 publishers2 min readPublished Updated
Insikt Group traces six months of Word macro lures on three governments to GRU's BlueDelta
The new backdoor, HOOKEDGE, is a Windows batch script that beacons to a free webhook.site endpoint. Insikt Group calls the BlueDelta attribution moderate confidence, resting on overlap with the older HEADLACE implant.
The Watch · Security desk

What happened
- Insikt Group dates a run of BlueDelta initial-access campaigns from late September 2025 to early April 2026, aimed at government and diplomatic organizations in Romania, Spain and Turkiye.
- Delivery was macro-enabled Microsoft Word documents carrying diplomatic-themed lures, which dropped HOOKEDGE, a lightweight Windows batch-script backdoor.
- Recorded Future attributes the activity with moderate confidence to BlueDelta, the GRU-linked group also tracked as APT28, Fancy Bear and Forest Blizzard.
Why it matters
- constraint There is no bespoke domain or VPS to take down, so the defensive work moves to egress inspection of a webhook service that legitimate engineering teams also call, which is a tuning problem rather than a takedown.
- decision Any ministry still allowing macro execution in internet-originated documents is choosing to leave open the only door this chain needs, and that policy sits above the detection budget.
- capability Splitting beacon rates by target value buys near-interactive tasking on selected hosts while the operation stays inside a free quota, so responsiveness costs the operators nothing.
- precedent A GRU-linked crew reducing its initial-access implant to a batch script sets the expectation for teams tuned to novel binaries: assume the next version is another script on somebody else's free tier.
HOOKEDGE's architecture is inherited. Insikt Group's link to BlueDelta rests on code and tradecraft overlap with HEADLACE, the backdoor the group used in earlier campaigns, plus consistent infrastructure patterns and targeting that matches Russian collection requirements [5]. Recorded Future rates that moderate confidence and says so in the assessment itself [4].
The delivery path is unglamorous: a macro-enabled Word document, a user who enables content, a batch file on disk [2]. Insikt's detection guidance names scheduled task abuse, headless Microsoft Edge execution and outbound connections to webhook services, which is where the chain touches the host and the wire [11].
The C2 is a developer testing utility. Every stage ran through webhook[.]site's free tier, the group's exclusive choice across these campaigns for command-and-control, payload staging and exfiltration [10]. That removes the dedicated infrastructure a responder would normally seize or blocklist, and it lets the traffic sit alongside legitimate requests [6].
The free tier also constrained the operators. Insikt attributes part of the implant's evolution to reduced free-tier API limits on webhook[.]site, alongside sandbox evasion [7]. The tiered beaconing follows from that: only targets assessed as having higher intelligence value received a second-stage payload with a much shorter interval, which kept the initial-access endpoints from being exhausted [9].
Late September 2025 to early April 2026 works out to roughly 187 days [17]. Across that window the changes were to lure documents, execution methods and beaconing intervals, with core functionality and the infrastructure model left alone [8]. Early lures impersonated Spanish government material; later ones dropped the pretext and simply asked users to enable macros [14]. Insikt reads this as refinement of existing tradecraft rather than new capability [12], which is consistent with a group that has been running espionage operations of this type for more than a decade [15].
The Spanish lure is the one with a calendar attached. It impersonated Spain's Ministry of the Presidency, Justice and Relations with the Cortes and was created shortly after a September 2025 meeting between Spanish and Moldovan officials [3]. Insikt raises Moldova's September 2025 parliamentary elections as a possible collection driver, and frames it as a possibility rather than a finding [18].
What the published summary does not carry is a victim count, or a statement that any organization in the three countries was successfully compromised [16]. Defense manufacturing sits in the target set alongside diplomatic bodies [13]. The mitigation list is cheap by the standards of GRU tooling: block macro execution for internet-originated documents, then alert on three behaviours a normal endpoint does not produce [11]. The variable that moved this implant twice was a SaaS provider's rate limit.
What to watch
- A further tightening of webhook.site free-tier limits, which has already driven two rounds of change in the implant.
- Publication of indicators or a victim count that shows whether any of the Romanian, Spanish or Turkish lures landed.
- HOOKEDGE turning up against targets outside the three countries named in this reporting.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence60
Perspective Coverage
3 publishers- Builder
- Builder 27%
- Operator
- Operator 68%
- Investor
- Investor 5%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Insikt Group identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain and Turkiye.
ReportedSupportedSource: Insikt Group / Recorded Future3 sources— create a free account to open themView cited source - [2]
The campaigns delivered HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Microsoft Word documents using diplomatic-themed lures.
- [3]
One lure impersonated material from Spain's Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 2025 meeting between Spanish and Moldovan officials.
- [4]
Insikt Group assesses with moderate confidence that the activity was conducted by BlueDelta, which overlaps with APT28, Fancy Bear and Forest Blizzard, a Russian state-sponsored group attributed to the GRU.
- [5]
The attribution is based on significant code and tradecraft overlap between HOOKEDGE and the HEADLACE backdoor used in prior BlueDelta campaigns, consistent infrastructure patterns, and targeting consistent with known Russian intelligence collection priorities.
- [6]
HOOKEDGE shares HEADLACE's core architecture, abusing legitimate webhook services for command-and-control, payload staging and data exfiltration, letting malicious activity blend with legitimate network traffic while reducing the overhead of dedicated infrastructure.
- [7]
The implant underwent continuous refinement between September 2025 and April 2026, likely to evade automated sandbox environments and to adapt to reduced free-tier API limits on webhook[.]site.
- [8]
BlueDelta introduced changes to lure documents, execution methods and beaconing intervals while maintaining HOOKEDGE's core functionality and infrastructure model.
- [9]
For targets assessed as having higher intelligence value, BlueDelta deployed a second-stage HOOKEDGE payload with a much shorter beaconing interval, giving operators more responsive tasking while keeping the webhook endpoints used for initial access from being exhausted.
- [10]
webhook[.]site's free tier was the group's exclusive choice for command-and-control, payload staging and exfiltration across these campaigns.
- [11]
Insikt Group recommends blocking macro execution from internet-originated documents and implementing detection coverage for scheduled task abuse, headless Microsoft Edge execution, and outbound connections to webhook services.
- [12]
Rather than introducing new capabilities, the group has steadily refined existing tradecraft, emphasizing operational resilience by adapting established tooling to evolving defensive measures and infrastructure constraints.
- [13]
The key findings describe the campaigns as targeting defense manufacturing and diplomatic organizations in Romania, Spain and Turkiye.
- [14]
Early activity impersonated Spanish government material, while later campaigns adopted generic macro-enablement lures.
- [15]
BlueDelta has conducted espionage-focused cyber operations for more than a decade, consistently targeting government, diplomatic, defense and policy-related organizations.
- [16]
The published executive summary and key findings state no victim count and no confirmed successful compromise at any named organization.
- [17]
The window from late September 2025 to early April 2026 spans roughly 187 days, about six months of continuous iteration on the same tooling.
- [18]
Insikt Group says the diplomatic lure's timing potentially reflects an effort to collect intelligence relevant to Russia ahead of Moldova's September 2025 parliamentary elections.
ReportedInsufficientSource: Insikt Group2 sources— create a free account to open themView cited source
Sources
3 independent publishers whose own reporting we read for this story.
- recordedfuture.comBlueDelta Targets Defense and Diplomacy with HOOKEDGE
1 article · August 26, 2026
- securityaffairs.comRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
1 article · August 28, 2026
- thehackernews.comAPT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
1 article · August 28, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Abuse of legitimate services for command-and-controlFollow
- State-Sponsored Cyber EspionageFollow
- Malicious Office macrosFollow
Entities
- Microsoft EdgeFollow
- Lab52Follow
- GRUFollow
- webhook.siteFollow
- Insikt GroupFollow
- HEADLACEFollow
- HOOKEDGEFollow
- APT28Follow
- Recorded FutureFollow