HOOKEDGE: A New Backdoor Aimed at European Government Networks, With Fingerprints Pointing to Russia
Recorded Future says a lightweight Windows script is being used against foreign ministries and government offices in Romania, Spain and Türkiye, with tentative links to the group tracked as APT28.

Key points
- Recorded Future's Insikt Group says a new backdoor called HOOKEDGE has been used against government and diplomatic targets in Romania, Spain and Türkiye between late September 2025 and early April 2026.
- HOOKEDGE is a small Windows batch script, meaning a simple text file of commands, that gives the attackers quiet remote access to infected machines.
- Researchers tie the activity, with medium confidence, to the Russian state-linked group tracked as APT28 (also called Fancy Bear or Sofacy by different vendors).
- The campaigns hit foreign ministries and diplomatic bodies, the classic target set for Russian military intelligence collection.
- No public victim count has been released, and the initial delivery method has not been fully detailed.
A new backdoor is quietly making the rounds inside European government networks, and analysts think Moscow is behind it.
Recorded Future's Insikt Group has published research on a piece of malware it calls HOOKEDGE. Malware is simply software written to do harm, and in this case the harm is spying. The tool has turned up on systems belonging to government and diplomatic organisations in Romania, Spain and Türkiye between late September 2025 and early April 2026.
HOOKEDGE is not flashy. It is a Windows batch script, essentially a plain text file full of commands the computer runs in order. That simplicity is the point. Small scripts are easy to hide, easy to change, and easy to slip past security tools that are hunting for bigger, noisier programs.
Once it lands on a machine, the script opens a quiet channel back to the attackers so they can issue further commands and pull information out.
Who is behind it?
Insikt Group links the campaigns, with medium confidence, to APT28, the Russian state-sponsored group most vendors agree sits inside Russia's military intelligence service, the GRU. Different companies use different names for the same crew: CrowdStrike calls it Fancy Bear, Microsoft tracks it as Forest Blizzard, and Mandiant uses APT28.
Medium confidence matters here. It means the analysts see overlapping infrastructure and tradecraft with past APT28 operations, but they are not calling it a lock. Attribution in this space almost never is. Groups share tools, copy each other's techniques, and sometimes deliberately plant false flags.
What is not in doubt is the target set. Foreign ministries, embassies and government offices are exactly the kind of collection targets Russian intelligence has hit for more than a decade.
What was targeted, and when?
| Country | Targeted sector | Reported window |
|---|---|---|
| Romania | Government and diplomatic | Late Sept 2025 to early Apr 2026 |
| Spain | Government and diplomatic | Late Sept 2025 to early Apr 2026 |
| Türkiye | Government and diplomatic | Late Sept 2025 to early Apr 2026 |
The three countries share something obvious: all sit on NATO's southern and eastern flank, and all handle sensitive diplomatic traffic on the war in Ukraine, energy policy, and Black Sea security. That is the sort of material Russian intelligence has openly prioritised.
The reporting, first published by The Hacker News based on Insikt Group's findings, does not yet spell out the exact initial access route. In previous APT28 campaigns, the group has favoured phishing emails, meaning fake messages designed to trick staff into opening a booby-trapped file or clicking a login page that steals their password. Whether HOOKEDGE arrives the same way is not yet confirmed.
Should ordinary people worry?
Not directly. This is espionage, not a consumer scam. The attackers want cables, memos and contact lists inside government buildings, not the bank details of a shopper in Madrid or a teacher in Bucharest.
The wider point is more sobering. A tiny batch script, well hidden, was enough to sit inside diplomatic networks across three countries for months. That tells you where the hard problem in defence still lies: not exotic zero-days, meaning secret software flaws, but patient operators using simple tools that blend into normal Windows activity.
Expect more detail as other vendors publish their own tracking under their own names.



