Skip to main content
CyberSingle-sourceMediumDeveloping
5.6

APT28-linked HOOKEDGE backdoor targets European government officials via malicious Word documents

The threat actor APT28 is deploying a two-stage backdoor, HOOKEDGE, against European diplomats and government entities using weaponized Word documents. The malware utilizes webhook.site for command-and-control and data exfiltration, with a tiered delivery mechanism that accelerates second-stage infection for high-value targets.

The Hacker Newsabout 16 hours agoRU, DE, FR, PLengCredibility 62%View source

Score Breakdown

Mosaic Score5.6
Confidence0.9
Significance0.5
Source credibility0.6

Intelligence Tags

Entities

countrycountrycountrycountry
Source

Related signals

8 found