A Word macro was the way in at defence manufacturers and government bodies

Microsoft Windows: Microsoft Windows 95 Version 4.00.1111 debug command 492x259
Image: Ghettoblaster (Public domain (opens in a new tab)). Source: Wikimedia Commons

Insikt Group, the threat research arm of Recorded Future, has mapped a campaign that ran from late September 2025 to early April 2026. The targets were defence manufacturers, government bodies and diplomatic organisations in Romania, Spain and Türkiye. The way in was macro-enabled Word documents, and what they planted was HOOKEDGE, a lightweight backdoor written as a Windows batch script. Insikt Group attributes the activity with moderate confidence to BlueDelta, an actor that overlaps with APT28, Fancy Bear and Forest Blizzard and is linked to Russia's military intelligence service, the GRU.

The backdoor kept its foothold through scheduled tasks. Command and control ran through Microsoft Edge and the webhook.site service, which also staged payloads and carried data out. Recorded Future advises security teams to block macros in documents that originate on the internet, to investigate scheduled tasks that run scripts from user-writable directories, to watch for unusual Microsoft Edge automation, and to review or restrict outbound connections to webhook services.

Word macro Document from outside Backdoor on host Scheduled task Orders via Edge webhook.site used The campaign ran from September 2025 to April 2026. Targets sat in Romania, Spain and Türkiye.
Figure: How Insikt Group describes the sequence. Command and control ran through a service developers use every day.

What this means for you if you control Office macros

Macros are an old road in, and that is exactly why this campaign is worth noting. A ban that lives in a policy document but not in the settings on the machines stops nothing. Our assessment is that the finding says more about the distance between paper and practice than about any new technique. The attackers needed no vulnerability. They needed a recipient who was allowed to run what a document contained.

The choice of channel is the second thing to take away. A webhook service is something developers use daily, and traffic to it looks ordinary in the logs. If you have no picture of which cloud services your machines talk to, this is the channel that slips past. The sources describe targets in three countries and a few sectors, yet the method is tied to neither.

Berigo recommends

  • Turn off macros in documents that arrive from outside, and verify the setting on the machines rather than in the documentation.
  • Look for scheduled tasks that run scripts from directories your users can write to.
  • Watch for Microsoft Edge starting when nobody has opened a browser.
  • Map which webhook services the organisation actually needs, and close the rest in outbound traffic.
  • Bring this campaign into the next exercise you run on a document from an unknown sender.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch