Decision RecordActivePublished without chair review
CRT-2026-027010 Sep 2026AFTERNOON EDITIONDaily Roundtable
HOOKEDGE egress and detection controls
Block access to webhook.site where there is no business need and alert on the reported sequence from Office documents through script execution and scheduled tasks to Edge-based webhook traffic.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Partially supportedThe account observed on September 10, 2026 describes HOOKEDGE activity from September 2025 through April 2026 using ordinary cloud and browser traffic to conceal command polling and exfiltration.
Because the reported controls rely on observable behavior—macro-enabled Word activity, batch/VBS execution, scheduled tasks, webhook.site, and Microsoft Edge traffic—they can be applied without resolving the disputed APT28 attribution.
The primary campaign report and validating telemetry remain missing, so the immediate rationale is exposure reduction and detection based on reported tradecraft, not proven control performance or evidence of activity after April 2026.
Who is affected
Partially supportedRomanian government, diplomatic, and defense users and their endpoint, network, and egress operators are named as reported targets; their exposure is the chain from macro-enabled Word lures through batch/VBS execution and scheduled-task persistence to webhook.site command polling and Microsoft Edge form-based exfiltration.
Spanish government, diplomatic, and defense users and operators face the same reported chain. Turkish government, diplomatic, and defense users and operators face the same reported chain.
Other European government, diplomatic, and defense institutions can apply the controls preventively, but the packet does not establish that they were targeted. Deployments that permit webhook.site without a business need are within the denial condition; deployments with a documented need are not.
No Microsoft Office, Word, or Edge version range is identified, so monitoring is behavior-based rather than version-based.
What supports this
Partially supported1) Support — The dated geopolitical campaign account reports that, from September 2025 to April 2026, HOOKEDGE used macro-enabled Word lures, batch/VBS payloads, scheduled-task persistence, webhook.site command polling, and Microsoft Edge forms for exfiltration against Romanian, Spanish, and Turkish government, diplomatic, and defense targets.
It describes concealment inside ordinary cloud and browser traffic. 2) Support — The first evidence review finds that the cited analysis explicitly recommends denying unnecessary webhook.site access and alerting on the reported Office, script-execution, scheduled-task, and Edge-traffic sequence.
3) Evidence gap — The second evidence review finds only an analyst summary, with no primary campaign report or independent telemetry proving that the sequence reliably catches HOOKEDGE or that the control is high-signal.
How the Roundtable reached this
Partially supportedGeopolitical analyst Elena Rossi surfaced the reported September 2025–April 2026 HOOKEDGE chain and its use against Romanian, Spanish, and Turkish government, diplomatic, and defense targets.
The decision scout separated immediately usable controls from the less certain APT28 attribution.
One evidence review confirmed that the cited analysis explicitly recommends denying unnecessary webhook.site access and alerting on the Office-to-script-to-scheduled-task-to-Edge sequence; another challenged any stronger claim that this sequence reliably catches HOOKEDGE because no primary campaign report or independent telemetry was supplied.
The boundary review found the defensive guidance publicly safe when framed as reported tradecraft. The linker found no prior decision target. The arbiter accepted a new operational decision, retaining the evidence limitation rather than treating control effectiveness or attribution as established.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 12 candidate signals.
- Linker (AI panel role)Linker evaluated 12 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 33 evidence signals; 21 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
- Arbiter (AI panel role)Arbiter produced 12 decision envelopes.
Key disagreement
Scout (AI panel role)
Attribution to APT28 is moderate confidence because direct operator identity and state-tasking evidence are unavailable and copycat activity remains plausible.
Arbiter outcome
Arbiter outcome: new decision record. The defensive egress and detection controls are directly supported, operationally clear, and publicly safe when described as guidance based on reported tradecraft.
Candidates considered
Considered 12 candidates · opened 1 · 11 not opened (11 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
ConflictingThe packet does not establish that the reported sequence reliably detects HOOKEDGE or that webhook.site is always a high-signal indicator; those claims need the missing primary report or telemetry.
Attribution to APT28 remains moderate confidence because direct operator-identity and state-tasking evidence is unavailable and copycat activity remains plausible.
The reporting names no affected Microsoft Office, Word, or Edge versions and does not show whether the activity continued after April 2026 or extended beyond Romania, Spain, and Turkey.
What evidence is missing
ConflictingThe packet lacks the primary HOOKEDGE campaign report and endpoint or network telemetry independently documenting the reported chain or measuring the controls’ effectiveness.
It supplies no correlation window or tested Microsoft Office, Word, or Edge versions for engineering the alert.
It also lacks direct evidence identifying the operator or showing state tasking, and it does not establish activity after April 2026 or targeting beyond the named Romanian, Spanish, and Turkish populations.
What would change this
WeakA documented business need for webhook.site changes application of the denial control for that deployment; the blanket-denial condition applies only where access is unnecessary.
A primary campaign report or independent telemetry that contradicts the reported Word-to-script-to-scheduled-task-to-Edge sequence would require revising the alert logic.
Evidence measuring poor detection performance would weaken the campaign-specific recommendation, while validating telemetry would strengthen it. Direct operator or state-tasking evidence would change the APT28 attribution assessment without automatically changing the defensive controls.
What to watch next
WeakWatch for any webhook.site connection from a network or host with no business need and block or investigate it.
Prioritize hosts where macro-enabled Word activity is followed by batch/VBS execution, scheduled-task creation, and Microsoft Edge webhook traffic; review the full chain when that trigger appears.
Watch for publication of the primary campaign report or supporting telemetry and use it to validate and tune the sequence. Revise attribution only if direct operator-identity or state-tasking evidence appears.
Evidence basis
Public value history
- 10 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 10 Sep 2026Methodology
How the panel reaches a Public Decision Record.