APT28 Explained: HOOKEDGE, TTPs and How to Defend in 2026
Table of contents
- 1. The word "sophisticated" is doing real damage
- 2. What APT28 actually did in 2026
- HOOKEDGE: a batch script and a webhook
- CVE-2026-21509: a one-day, weaponised in a day
- Roundcube: no click required
- The long game in Ukraine
- The genuinely novel one
- 3. What they are actually good at, which is not what you think
- 4. Nobody can agree what to call them, and that is your problem too
- 5. Are you an APT28 target? Probably not.
- 6. What actually works
- 7. One honest caveat
- FAQs
What does it take to run a persistent espionage operation inside European government, diplomatic and defense manufacturing networks? In 2026, considerably less than the phrase “advanced persistent threat” would lead you to expect.
HOOKEDGE is a Windows batch script.
It arrives in a macro-enabled Word document. It asks the recipient to click Enable Content. It has no dedicated command and control server, because it uses a free public webhook testing service instead. And it talks to that service by opening Microsoft Edge, either headless or shrunk to a one-pixel window pushed off the edge of the screen.
This previously undocumented backdoor was used against targets in Romania, Spain and Türkiye between late September 2025 and early April 2026, with fresh variants appearing in June and July. Security researchers attribute it with moderate confidence to a Russian state-sponsored group that overlaps with APT28, Fancy Bear and Forest Blizzard, assessed by the UK’s National Cyber Security Centre in April as almost certainly GRU Unit 26165.
That is the current state of the art in Russian military intelligence espionage against European governments. A .bat file, a macro, and a browser window you cannot see.
1. The word “sophisticated” is doing real damage
Search for APT28 and you will find perhaps forty vendor profiles that open with some variation of the same sentence; Highly sophisticated, Advanced persistent threats, nation-state actor etc.
Once a security team accepts that framing, a specific and unhelpful thing happens. APT28 stops being a defensive problem and becomes a geopolitical weather event.
Look at what the 2026 campaigns actually required from the victim.
Someone had to open a Word attachment. Someone had to click Enable Content. Someone had to be running a webmail server with an unpatched cross-site scripting flaw. Someone had to still be exposed to a Microsoft Office vulnerability a day after the patch shipped.
None of those are unsolvable. That is precisely the problem, because boring problems are the ones organizations defer, and the deferral is what the GRU is actually exploiting.
2. What APT28 actually did in 2026
Here is the year, without the adjectives.
HOOKEDGE: a batch script and a webhook
Insikt Group’s research, reported in August, describes HOOKEDGE as a lightweight Windows batch-script backdoor distributed through macro-enabled Word documents with diplomatic-themed lures. The earliest known lure impersonated a meeting agenda from Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, and appeared shortly after a real meeting between Spanish and Moldovan officials. Targets were in Romania, Spain and Türkiye.
The execution chain is almost aggressively unglamorous. Enabling macros writes script files to the user profile directory and creates a Windows Scheduled Task. The document then displays a fake Microsoft Word error message so the odd behaviour looks like a corrupted file rather than a compromise.
For command and control, HOOKEDGE spins up Microsoft Edge, either headless or positioned off-screen at a one-by-one pixel size, and uses it to poll webhook.site, a free public service intended for testing webhooks. Output goes back the same way, through an automatically rendered HTML form. There is no attacker-owned server to block, no unusual protocol, and no binary for signature-based detection to catch, because the payload is a text file made of commands Windows ships with.
Insikt Group also observed two tiers of victim handling. A first-stage implant beacons every 30 minutes and helps operators work out who is worth more attention. Systems assessed as higher value receive a second-stage instance checking in as often as every five minutes. Researchers assess HOOKEDGE as a direct evolution of the earlier HEADLACE backdoor.
CVE-2026-21509: a one-day, weaponised in a day
In January, APT28 ran a campaign against European military and government entities, with a focus on maritime and transport organizations in Poland, Slovenia, Türkiye, Greece, the UAE and Ukraine. Trellix documented the chain: a Microsoft Office flaw weaponised within 24 hours of its public disclosure, delivered by spear phishing, dropping an Outlook VBA backdoor called NotDoor and a modified Covenant implant, with the legitimate cloud storage service filen.io used for command and control. CERT-UA attributed the January wave to UAC-0001.
Note the detail that matters. This was a one-day, not a zero-day. The patch existed. APT28’s advantage was not that they found something nobody knew about. It was that they moved faster than the patch cycle of European government IT.
Roundcube: no click required
In April, Ukrainian authorities confirmed a long-running campaign against prosecutors and anti-corruption agencies, which officials believe is linked to APT28 and which CERT-UA has tracked across three waves since 2023. The intrusions exploited vulnerabilities in Roundcube, the open-source webmail platform, executing code when a victim simply opened an email. No click. No download.
Roundcube is self-hosted. Which means the vulnerable component was an internet-facing server that somebody in each of those organizations was responsible for patching, and did not.
The long game in Ukraine
In March, ESET reported that APT28 had been using paired BeardShell and Covenant implants alongside a SlimAgent keylogger against Ukrainian military personnel since April 2024. Two years of access. SlimAgent is assessed to have evolved from XAgent, tooling the group has used for a decade.
The genuinely novel one
One 2026-adjacent development does deserve the word new. LAMEHUG, analysed by Cato Networks in July 2025 and linked to APT28, is described as the first known malware to use a large language model to generate the commands it executes on compromised Windows systems.
That is a real first, and worth watching. It is also one item on a list where everything else is a Word macro.
3. What they are actually good at, which is not what you think
Strip out the tooling and two capabilities remain. Neither is technical.
Speed. Twenty-four hours from public disclosure to weaponised exploit is genuinely difficult. It requires standing capacity, a triage process, and a delivery pipeline already built and waiting. Very few groups can do it. This is the capability that should worry defenders, and it is one that no amount of sophistication in the malware would replace.
Patience. HOOKEDGE ran for roughly seven months with iterative refinement to lures, execution chain and C2 methods, then produced new variants two months later. The Ukrainian military campaign has run since April 2024. The Roundcube activity spans three waves since 2023. These are not smash-and-grab operations, and the two-tier beaconing design shows a group that expects to be inside long enough for triage to be worth the effort.
Speed and patience are organizational properties, not technical ones. You cannot buy a product that counters them. What you can do is remove the openings they rely on, and those openings are ordinary.
4. Nobody can agree what to call them, and that is your problem too
MITRE’s entry for this group lists APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE and GruesomeLarch. Add BlueDelta from Recorded Future, UAC-0001 from CERT-UA, and APT-C-20 from Chinese researchers, and you are approaching twenty names for one organizational unit.
This is usually presented as trivia. It is not trivia.
If your threat intelligence platform ingests a Recorded Future report on BlueDelta, a CERT-UA advisory on UAC-0001, a Microsoft bulletin on Forest Blizzard and an ESET paper on Sednit, you have four records describing one adversary. Correlation depends on whether someone maintained an alias mapping. In practice the alias tables are incomplete, and campaigns that are actually one continuous operation get filed as four unrelated ones.
The naming exists because vendors name what they discover independently, which is defensible. But the cost lands on the defender, not the vendor, and the industry has been comfortable with that arrangement for a long time.
Practical version: when you build detections or brief an executive, work from the GRU unit rather than the vendor codename. Unit 26165 is APT28. Unit 74455 is Sandworm, a different organization with different objectives. Conflating the two is a common error in reporting, and it leads to defensive priorities that make no sense.
5. Are you an APT28 target? Probably not.
Most articles about state actors imply that everyone is at risk. It generates urgency and it sells. It is also, for the majority of readers, untrue.
APT28’s victimology is consistent to the point of monotony: government ministries, diplomatic missions, defense manufacturers, military personnel, prosecutors, and organizations connected to Ukraine or NATO policy. The group prioritises intelligence collection and persistence over destructive attacks. If you make industrial fasteners in Baden-Württemberg and sell to domestic customers, GRU Unit 26165 has not heard of you and is not going to.
There are three ways that changes.
- You are in the logistics or transport chain. The January campaign focused on maritime and transport organizations, and a 2025 joint advisory covered targeting of Western logistics and technology companies involved in aid to Ukraine. These are private companies, not ministries.
- You supply a target. Defense manufacturing sits explicitly in scope, and manufacturing supply chains run deep. Your customer’s threat model becomes yours the moment you hold their drawings, schedules or correspondence.
- You are collateral. A compromised webmail server or a mailbox in an unrelated organization is useful as infrastructure. You do not need to be the objective to be in the path.
If none of those apply, the correct response to APT28 coverage is professional interest rather than budget reallocation. Being told that honestly is more useful than being told you are in the crosshairs.
6. What actually works
Because the tradecraft is ordinary, the countermeasures are too. This is good news that reads like bad news.
- Block macros from the internet. Both HOOKEDGE and the CVE-2026-21509 chain start with a macro-enabled Office document. Microsoft has blocked these by default for years and the default still gets overridden constantly.
- Patch internet-facing mail infrastructure first. Roundcube, Zimbra, Horde and similar self-hosted platforms have been APT28’s preferred surface for years. A webmail server exploitable on email preview is a critical asset regardless of what your CVSS scoring says.
- Shorten your one-day window. You cannot patch faster than 24 hours across an estate. You can know within 24 hours which of your exposed assets are affected, which is a different and achievable problem.
- Alert on legitimate services used illegitimately. webhook.site, filen.io and comparable free platforms are the C2 layer here. Blanket blocking is usually impractical, but a headless browser process posting to a webhook testing service is not normal user behaviour and is detectable as such.
- Know what mail infrastructure you actually run. The Roundcube instance that gets exploited is generally the one a team stood up years ago and forgot. Attack Surface Management finds internet-facing assets from the outside, which is the same view the attacker has.
- Watch your credentials. This group’s goal is persistent access to correspondence, and stolen credentials are how that persists after the malware is removed. Credential Intelligence surfaces exposed pairs tied to your domains.
Nothing on that list is novel, and that is the argument of this entire article. The gap between APT28’s tooling and your defences is not a capability gap. It is a follow-through gap.
7. One honest caveat
Everything above describes what has been published. It does not describe what APT28 can do.
Public reporting is inherently biased toward operations that were detected. A group with a genuinely advanced capability would use it selectively, against targets where the intelligence justified burning it, and the rest of the time would reach for a batch script because a batch script works. The absence of exotic tooling in the public record is weak evidence about the tooling that exists.
Attribution deserves the same care. HOOKEDGE is attributed to this group with moderate confidence, not high confidence. Ukrainian officials describe the Roundcube campaign as believed to be linked to APT28. Those hedges are in the source material and they belong in any honest summary of it.
So the claim is narrower than the headline: not that APT28 is incapable, but that its documented 2026 European operations succeeded using techniques any competent security programme can already counter. Which makes the failure a defensive one, and defensive failures are the kind you can fix.
FAQs
No, and the confusion is common. Both are Russian military intelligence, but APT28 is assessed as GRU Unit 26165 and Sandworm as Unit 74455. APT28 does espionage and prioritises quiet persistence. Sandworm has a documented history of destructive operations including wipers and attacks on electrical infrastructure. Different units, different objectives, different defensive priorities.
Because vendors and national CERTs name intrusion sets independently as they discover them. Fancy Bear came from CrowdStrike, Forest Blizzard from Microsoft, BlueDelta from Recorded Future, Sednit from ESET, UAC-0001 from CERT-UA, STRONTIUM from Microsoft’s older taxonomy. There are close to twenty aliases in circulation. It is a correlation problem for anyone ingesting multiple intelligence feeds, not just a naming curiosity.
HOOKEDGE is a lightweight Windows batch-script backdoor delivered through macro-enabled Word documents, assessed as an evolution of the earlier HEADLACE backdoor. Detection opportunities cluster around behaviour rather than files: a Scheduled Task created shortly after an Office document opens, script files written to the user profile directory, and Microsoft Edge launched headless or at a one-by-one pixel size to reach webhook.site. Refer to Recorded Future’s Insikt Group research for current indicators.
Historically yes, and it retains that capability. But its 2026 European campaigns leaned on one-days and known vulnerabilities. CVE-2026-21509 was weaponised within 24 hours of public disclosure, meaning the patch already existed. The operational advantage came from speed against slow patch cycles rather than from undisclosed vulnerabilities.
Directly, probably not. APT28’s targeting is consistently governmental, diplomatic, military and Ukraine-adjacent. The exceptions worth checking are logistics and transport companies, technology suppliers to those sectors, and defense manufacturing supply chains, all of which have appeared in recent targeting. If you are outside those, the useful takeaway is not that APT28 is coming for you. It is that the openings it exploited, unpatched webmail and enabled macros, are the same ones ransomware operators use, and those groups genuinely are indiscriminate.
Whichever adversary you are actually facing, the first question is the same: what of yours is reachable from the internet right now, and do you know about all of it?
