Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Russian APT BlueDelta leverages webhook.site and Microsoft Edge to conceal command-and-control communications for HOOKEDGE espionage operations targeting European government defense and diplomatic entities. The group, linked to Russia's GRU and overlapping with APT28, exploits the legitimate webhook testing service to hide malicious traffic from detection. Recorded Future's Insikt Group documented the campaign, revealing how the threat actor abuses developer tools to conduct sustained espionage against European government infrastructure.
North Korean remote workers are expanding beyond traditional IT roles into sales, marketing, and medical positions, according to Huntress research. These actors present a distinctive threat vector by securing legitimate remote employment and performing their assigned duties rather than immediately compromising systems, making them difficult to detect through conventional security controls. The threat highlights how nation-state actors are diversifying their workforce infiltration strategies across multiple business functions.
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via
US authorities have disrupted a Chinese hacking platform operated by a group named QTFY that provided offensive cyber services to the Chinese government and other clients. The platform was actively used to conduct attacks against military and critical infrastructure targets, according to the operation details.
The pro-Russian hacker group Server Killers claimed responsibility for the attack. The post Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services appeared first on SecurityWeek.