APT28과 연결된 HOOKEDGE 백도어가 유럽 정부를 타겟으로 하고 있다.
사이버 보안 연구자들은 2025년 9월 말부터 2026년 4월 초까지 루마니아, 스페인, 튀르키예의 정부 및 외교 기관을 타겟으로 하는 새로운 사이버 공격 캠페인을 발견했다. 이 캠페인에서 배포된 HOOKEDGE라는 이름의 백도어는 Windows 배치 스크립트로 구성되어 있다. Recorded Future Insikt Group의 연구에 따르면, 이 백도어는 문서화되지 않은 것으로 현재 진행 중인 공격에 사용되고 있다.
APT28-linked HOOKEDGE backdoor targets European governments.
Cybersecurity researchers have identified a new set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Turkey from late September 2025 to early April 2026. These campaigns have led to the deployment of a previously undocumented backdoor known as HOOKEDGE, which is a lightweight Windows batch script. According to Recorded Future Insikt Group's research, this backdoor is currently being utilized in ongoing attacks.