Russia's GRU Spies on NATO Using Microsoft Edge as Cover
Russia's military intelligence agency, GRU, has been accused of running a seven-month espionage campaign against defense manufacturing and diplomatic networks in three NATO member states. According to researchers at Recorded Future's Insikt Group, the malware used in this campaign is called HOOKEDGE, which was deployed between late September 2025 and April 2026. The HOOKEDGE backdoor functions as a Windows batch script that issues commands and sends stolen data through Microsoft Edge, the browser bundled with every modern Windows installation.
The reason HOOKEDGE is drawing attention is its ability to blend into the noise of normal web browsing traffic. By routing its network traffic through a legitimate, digitally signed, enterprise-trusted browser process, the malware makes its communications functionally indistinguishable from an employee browsing the web. This evasion strategy is an extension of a technique called living off the land, which involves repurposing trusted, pre-installed tools rather than introducing foreign malicious code.
The campaign's earliest identified lure impersonated a meeting agenda from Spain's Ministry of the Presidency, Justice and Relations with the Cortes. The document was created 18 days after an actual September 8, 2025 meeting between Spanish and Moldovan officials, demonstrating that BlueDelta had near-real-time visibility into EU diplomatic activity.