Back to all lessons
Awareness Lessons
last month

APT28 Deploys HOOKEDGE Backdoor via Malicious Word Documents Against European Governments

APT28, a Russian state-sponsored threat actor, is targeting European government and diplomatic organizations by weaponizing Microsoft Word documents to deliver the HOOKEDGE backdoor. The malware leverages webhook.site — a legitimate web service — for command-and-control communication, effectively blending malicious traffic with normal web activity and bypassing traditional detection tools. This campaign highlights the danger of trusting seemingly legitimate file attachments and the difficulty of detecting threats that abuse trusted third-party services. Without robust email filtering, user awareness, and behavioral monitoring, such campaigns can persist undetected for extended periods, giving adversaries deep access to sensitive government networks.

Tactical Insight

Immediate actions

  • Block or restrict outbound connections to known webhook and free-tier web service domains (e.g., webhook.site) at the perimeter firewall.
  • Deploy email security solutions with sandboxing capabilities to detonate and inspect all incoming Office document attachments before delivery.
  • Issue an urgent advisory to staff in government and diplomatic roles warning them not to enable macros or editing in unsolicited Word documents.

Long-term improvements

  • Enforce a Group Policy or Intune policy to disable macro execution in Microsoft Office documents received from external sources.
  • Implement application allowlisting to prevent unauthorized executables spawned by Office applications from running on endpoints.
  • Conduct regular phishing simulation exercises tailored to spear-phishing tactics used by nation-state actors like APT28.

Detection measures

  • Deploy EDR/XDR solutions configured to alert on Office applications spawning unusual child processes or making unexpected outbound network connections.
  • Monitor and alert on DNS/HTTP traffic to free webhook, pastebin, or similar services originating from internal government endpoints.
  • Establish behavioral baselines for government workstations and flag anomalous outbound communication patterns consistent with C2 beaconing.