The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

Hooked on Espionage: BlueDelta Targets Europe with HOOKEDGE

Sep 4, 2026, 2:35:10 PM / by The Hivemind posted in Threat Bulletin, Fancy Bear, APT28, BlueDelta, Forest Blizzard, Russian cyberespionage, Russian GRU, BlueDelta malware, HOOKEDGE malware

0 Comments

Verticals Targeted: Government, Diplomacy, Defense Manufacturing
Regions Targeted: Romania, Spain, Turkey, Europe
Related Malware: HEADLACE

Executive Summary

Russian state-sponsored threat group BlueDelta deployed the HOOKEDGE Windows backdoor in espionage campaigns targeting European diplomatic, government, and defense-related organizations. Delivered through macro-enabled Microsoft Word documents, HOOKEDGE uses scheduled tasks, Microsoft Edge, and legitimate webhook services for C2, payload staging, and data exfiltration. The campaigns demonstrate BlueDelta’s continued refinement of established tradecraft to evade detection, minimize infrastructure requirements, and selectively escalate activity against targets assessed as having higher intelligence value.

Read More

Rise of the AI-Enabled Malware

Nov 10, 2025, 1:41:22 PM / by The Hivemind posted in Threat Bulletin, Data Exfiltration, AI-enabled malware, LLM misuse, FRUITSHELL, PROMPTFLUX, PROMPTLOCK, dynamic obfuscation, state-sponsored AI, PROMPTSTEAL, QUIETVAULT, APT28, Gemini API abuse

0 Comments

Verticals Targeted: None Specified
Regions Targeted: Ukraine
Related Families: FRUITSHELL, PROMPTFLUX, PROMPTLOCK, PROMPTSTEAL, QUIETVAULT

Executive Summary

Industry researchers have noted the emergence of AI-integrated malware that queries large language models during runtime to generate code, obfuscate payloads, and adapt behaviors. This evolution extends beyond productivity aids, enabling nation state actors and cybercriminals to enhance intrusion chains with dynamic capabilities. Associated malware includes FRUITSHELL, PROMPTFLUX, PROMPTLOCK, PROMPTSTEAL, and QUIETVAULT.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts