Recorded Future's Insikt Group reports that a Russian state-sponsored campaign using the HOOKEDGE backdoor likely targeted government or diplomatic institutions in Romania. Related activity also targeted diplomatic audiences in Spain and Türkiye. The research links the operation with moderate confidence to BlueDelta, a cluster that overlaps with APT28, Fancy Bear and Forest Blizzard.
The public evidence does not identify a Romanian institution or confirm that every lure produced a successful compromise. It does show a campaign built to turn a trusted diplomatic document and an ordinary Windows endpoint into a persistent command and data channel. Recovery therefore has to rebuild endpoint and credential trust, not merely delete the original attachment.
What the original research reports
Insikt Group identified macro-enabled Word documents used between late September 2025 and early April 2026 in campaigns against European government and diplomatic personnel. Spanish-themed lures were followed by more generic documents instructing recipients to enable content. Based on the observed campaign pattern, the researchers assess that the later activity likely targeted institutions in Romania; April variants were associated with targets in Türkiye.
When a recipient enabled the macro, the installer created scheduled-task persistence and deployed HOOKEDGE, a lightweight Windows batch backdoor. It used hidden or headless Microsoft Edge processes and a legitimate webhook service to receive commands and return output. The operators could deploy a faster-beaconing second stage for targets considered more valuable.
Recorded Future says the code and tradecraft significantly overlap with HEADLACE and assesses with moderate confidence that HOOKEDGE is its evolutionary successor. The attribution and target interpretation are intelligence assessments, not public victim confirmations from the Romanian government.
Why diplomatic recovery has a credential-channel problem
A compromised diplomatic workstation can execute commands and stage local data for exfiltration. Depending on what the user and endpoint could access, that may place email sessions, VPN credentials, document-system tokens, contact material and incident-room recovery values within reach. The public report does not establish that any specific credential was stolen, so rotation should follow an evidence-based reachability map.
The more immediate mistake is to issue replacements through the same endpoint, mailbox or collaboration account under investigation. If persistence or a stolen session remains, a newly generated password can become the attacker's newest credential. A clean recovery channel requires independent participant verification, a known-clean device and a delivery path outside the suspected account set.
A clean recovery sequence for targeted institutions
- Preserve the affected endpoint. Capture volatile and disk evidence, email metadata, Office telemetry, scheduled tasks, browser processes and outbound network records.
- Contain accounts and sessions. Disable or restrict the affected identity, revoke active sessions and isolate the device without using it to coordinate recovery.
- Hunt the complete delivery chain. Review macro-enabled attachments, suspicious user-directory files, scripted scheduled tasks, hidden browser execution and unexpected webhook traffic.
- Identify lateral reach. Determine which mailboxes, VPNs, file repositories, document systems and administrative services were available from the endpoint.
- Establish known-clean administration. Use separately verified devices, networks and identities before generating replacement credentials.
- Rotate in dependency order. Replace identity and recovery authorities first, followed by email, VPN, document-system, service and lower-privilege credentials.
- Verify recipients out of band. Use pre-established contacts and two-person approval for high-impact diplomatic or administrative access.
- Keep replacement plaintext out of the incident transcript. Record who authorized and received a value without copying the value into email, chat or a case-management archive.
Where Secretus fits—and where it does not
Secretus can deliver a temporary password, recovery code or API token through a one-time link after the response team has verified a clean sender, recipient and endpoint. This reduces the durable plaintext left in a diplomatic email or incident-room history while allowing the case record to preserve authorization and custody.
Secretus does not detect HOOKEDGE, remove persistence or protect a value opened on a compromised workstation. It is a handoff control inside a larger recovery process. The endpoint, browser, identity and network path must be independently trusted before the replacement secret is delivered.
What remains unknown
Public reporting does not name the Romanian organizations, state how many recipients opened the documents, quantify successful compromises or identify the information exfiltrated. It does not prove that BlueDelta obtained credentials from a Romanian institution. The BlueDelta/APT28 link and Romanian targeting are Recorded Future assessments with stated confidence levels and should remain attributed as such.
