type: incident · created: 2026-08-29 · updated: 2026-08-29 · tags: [incident, espionage, apt28, bluedelta, russia, government, backdoor] · confidence: high · affected_sectors: [government, defence] · au_impact: true
APT28-Linked BlueDelta Targets European Governments With HOOKEDGE
Recorded Future's Insikt Group detailed a series of Russian GRU-aligned BlueDelta (APT28) initial-access campaigns between late September 2025 and early April 2026 against government and diplomatic organisations in Romania, Spain and Türkiye. The campaigns delivered a lightweight Windows batch-script backdoor dubbed HOOKEDGE — sharing code and tradecraft overlap with BlueDelta's earlier tooling.
| Attribute | Detail |
|---|---|
| Actor | BlueDelta (APT28, GRU-aligned) |
| Windows | Late Sep 2025 – early Apr 2026 |
| Targets | Government + diplomatic orgs in Romania, Spain, Türkiye |
| Implant | HOOKEDGE (Windows batch-script backdoor) |
| Tradecraft | Code/technique overlap with BlueDelta's earlier tooling |
| Source | Recorded Future / Insikt — Tier 2/4 |
A classic state espionage initial-access series against European government and diplomatic targets — relevant intelligence for Five Eyes partners monitoring Russian GRU activity.