Researchers at Recorded Future have attributed a series of cyberattacks targeting government and diplomatic organizations in Romania, Spain, and Türkiye (between late 2025 and early 2026) to Russian state-sponsored group APT28, based on strong code and technique overlaps with the group's previously known tooling. The campaigns deploy a newly identified backdoor called HOOKEDGE — a Windows batch script delivered via macro-enabled Word documents — which uses webhook.site services for command-and-control, payload retrieval, and data exfiltration to blend in with normal network traffic. HOOKEDGE has been continuously refined over the campaign period and is considered a direct successor to APT28's earlier HEADLACE backdoor, with high-value targets receiving a more aggressive second-stage implant offering operators greater interactive control.