Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Russian APT BlueDelta Leverages HOOKEDGE Malware via Macro‑Laced Word Docs to Spy on European Defense & Diplomatic Bodies

BlueDelta ran a espionage campaign against government and diplomatic organizations in Romania, Spain and Türkiye, delivering a macro‑enabled Word document that installed the HOOKEDGE backdoor. The malware uses Microsoft Edge for covert command‑and‑control, highlighting the need for robust security‑awareness and access‑control evidence in SOC 2 audits.

LiveThreat™ Intelligence · 📅 August 28, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
Medium
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Russian APT BlueDelta Leverages HOOKEDGE Malware via Macro‑Laced Word Docs to Spy on European Defense & Diplomatic Bodies

What Happened — BlueDelta (linked to Russia’s GRU) ran a multi‑month espionage campaign (Sept 2025 – Apr 2026) against government and diplomatic entities in Romania, Spain and Türkiye. The group distributed macro‑enabled Microsoft Word files that installed a lightweight Windows batch‑script backdoor called HOOKEDGE. HOOKEDGE uses Microsoft Edge as a legitimate browser to pull commands and exfiltrate data through webhook.site, making its traffic blend with normal browsing.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits phishing‑based credential compromise, a classic failure of SOC 2 Access Control and Security Awareness criteria.
  • Continuous evidence of security‑awareness training and email‑filtering controls is required to demonstrate due diligence during a SOC 2 audit.
  • Verisq’s Security Awareness capability can provide automated training metrics and phishing‑simulation evidence that map directly to the relevant SOC 2 trust‑service criteria.

Who Is Affected — Government ministries, defense agencies, and diplomatic missions (public sector).

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (Security Awareness) and CC6.2 (User Access Management) controls; collect training completion logs as audit evidence.
  • Deploy macro‑blocking policies in Office, enforce least‑privilege for Edge, and enable network‑traffic monitoring for anomalous browser‑based C2.
  • Conduct a targeted phishing simulation using the same diplomatic‑themed lure to validate employee resilience.

Source: Security Affairs

Technical Notes

  • Attack vector: Phishing macro‑enabled Word documents → malicious batch script → Edge‑based C2 via webhook.site.
  • Malware: HOOKEDGE – Windows batch backdoor, scheduled task every 30 min, uses msedge.exe for command retrieval and data exfiltration.
  • Indicators: webhook.site URLs, scheduled task names, Edge process spikes, macro execution alerts.
📰 Original Source
https://securityaffairs.com/197996/apt/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →