Russian APT BlueDelta Leverages HOOKEDGE Malware via Macro‑Laced Word Docs to Spy on European Defense & Diplomatic Bodies
What Happened — BlueDelta (linked to Russia’s GRU) ran a multi‑month espionage campaign (Sept 2025 – Apr 2026) against government and diplomatic entities in Romania, Spain and Türkiye. The group distributed macro‑enabled Microsoft Word files that installed a lightweight Windows batch‑script backdoor called HOOKEDGE. HOOKEDGE uses Microsoft Edge as a legitimate browser to pull commands and exfiltrate data through webhook.site, making its traffic blend with normal browsing.
Why It Matters for Compliance & Audit Readiness
- The attack exploits phishing‑based credential compromise, a classic failure of SOC 2 Access Control and Security Awareness criteria.
- Continuous evidence of security‑awareness training and email‑filtering controls is required to demonstrate due diligence during a SOC 2 audit.
- Verisq’s Security Awareness capability can provide automated training metrics and phishing‑simulation evidence that map directly to the relevant SOC 2 trust‑service criteria.
Who Is Affected — Government ministries, defense agencies, and diplomatic missions (public sector).
Recommended Actions
- Map the incident to SOC 2 CC6.1 (Security Awareness) and CC6.2 (User Access Management) controls; collect training completion logs as audit evidence.
- Deploy macro‑blocking policies in Office, enforce least‑privilege for Edge, and enable network‑traffic monitoring for anomalous browser‑based C2.
- Conduct a targeted phishing simulation using the same diplomatic‑themed lure to validate employee resilience.
Source: Security Affairs
Technical Notes
- Attack vector: Phishing macro‑enabled Word documents → malicious batch script → Edge‑based C2 via webhook.site.
- Malware: HOOKEDGE – Windows batch backdoor, scheduled task every 30 min, uses
msedge.exefor command retrieval and data exfiltration. - Indicators: webhook.site URLs, scheduled task names, Edge process spikes, macro execution alerts.