Decision RecordActivePublished without chair review

HOOKEDGE egress and detection controls

HOOKEDGE campaign defense

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
Section support
0/8 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated today
Last revised 2026-09-10
Active2 evidence references · Published 10 Sep 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Block access to webhook.site where there is no business need and alert on the reported sequence from Office documents through script execution and scheduled tasks to Edge-based webhook traffic.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

At a glance

The edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.

02

Why now

Partially supported

The account observed on September 10, 2026 describes HOOKEDGE activity from September 2025 through April 2026 using ordinary cloud and browser traffic to conceal command polling and exfiltration.

Because the reported controls rely on observable behavior—macro-enabled Word activity, batch/VBS execution, scheduled tasks, webhook.site, and Microsoft Edge traffic—they can be applied without resolving the disputed APT28 attribution.

The primary campaign report and validating telemetry remain missing, so the immediate rationale is exposure reduction and detection based on reported tradecraft, not proven control performance or evidence of activity after April 2026.

03

Who is affected

Partially supported

Romanian government, diplomatic, and defense users and their endpoint, network, and egress operators are named as reported targets; their exposure is the chain from macro-enabled Word lures through batch/VBS execution and scheduled-task persistence to webhook.site command polling and Microsoft Edge form-based exfiltration.

Spanish government, diplomatic, and defense users and operators face the same reported chain. Turkish government, diplomatic, and defense users and operators face the same reported chain.

Other European government, diplomatic, and defense institutions can apply the controls preventively, but the packet does not establish that they were targeted. Deployments that permit webhook.site without a business need are within the denial condition; deployments with a documented need are not.

No Microsoft Office, Word, or Edge version range is identified, so monitoring is behavior-based rather than version-based.

04

What supports this

Partially supported

1) Support — The dated geopolitical campaign account reports that, from September 2025 to April 2026, HOOKEDGE used macro-enabled Word lures, batch/VBS payloads, scheduled-task persistence, webhook.site command polling, and Microsoft Edge forms for exfiltration against Romanian, Spanish, and Turkish government, diplomatic, and defense targets.

It describes concealment inside ordinary cloud and browser traffic. 2) Support — The first evidence review finds that the cited analysis explicitly recommends denying unnecessary webhook.site access and alerting on the reported Office, script-execution, scheduled-task, and Edge-traffic sequence.

3) Evidence gap — The second evidence review finds only an analyst summary, with no primary campaign report or independent telemetry proving that the sequence reliably catches HOOKEDGE or that the control is high-signal.

05

How the Roundtable reached this

Partially supported

Geopolitical analyst Elena Rossi surfaced the reported September 2025–April 2026 HOOKEDGE chain and its use against Romanian, Spanish, and Turkish government, diplomatic, and defense targets.

The decision scout separated immediately usable controls from the less certain APT28 attribution.

One evidence review confirmed that the cited analysis explicitly recommends denying unnecessary webhook.site access and alerting on the Office-to-script-to-scheduled-task-to-Edge sequence; another challenged any stronger claim that this sequence reliably catches HOOKEDGE because no primary campaign report or independent telemetry was supplied.

The boundary review found the defensive guidance publicly safe when framed as reported tradecraft. The linker found no prior decision target. The arbiter accepted a new operational decision, retaining the evidence limitation rather than treating control effectiveness or attribution as established.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 12 candidate signals.
  • Linker (AI panel role)Linker evaluated 12 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 33 evidence signals; 21 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 12 decision envelopes.

Key disagreement

Scout (AI panel role)

Attribution to APT28 is moderate confidence because direct operator identity and state-tasking evidence are unavailable and copycat activity remains plausible.

Arbiter outcome

Arbiter outcome: new decision record. The defensive egress and detection controls are directly supported, operationally clear, and publicly safe when described as guidance based on reported tradecraft.

Candidates considered

Considered 12 candidates · opened 1 · 11 not opened (11 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Conflicting

The packet does not establish that the reported sequence reliably detects HOOKEDGE or that webhook.site is always a high-signal indicator; those claims need the missing primary report or telemetry.

Attribution to APT28 remains moderate confidence because direct operator-identity and state-tasking evidence is unavailable and copycat activity remains plausible.

The reporting names no affected Microsoft Office, Word, or Edge versions and does not show whether the activity continued after April 2026 or extended beyond Romania, Spain, and Turkey.

07

What evidence is missing

Conflicting

The packet lacks the primary HOOKEDGE campaign report and endpoint or network telemetry independently documenting the reported chain or measuring the controls’ effectiveness.

It supplies no correlation window or tested Microsoft Office, Word, or Edge versions for engineering the alert.

It also lacks direct evidence identifying the operator or showing state tasking, and it does not establish activity after April 2026 or targeting beyond the named Romanian, Spanish, and Turkish populations.

08

What would change this

Weak

A documented business need for webhook.site changes application of the denial control for that deployment; the blanket-denial condition applies only where access is unnecessary.

A primary campaign report or independent telemetry that contradicts the reported Word-to-script-to-scheduled-task-to-Edge sequence would require revising the alert logic.

Evidence measuring poor detection performance would weaken the campaign-specific recommendation, while validating telemetry would strengthen it. Direct operator or state-tasking evidence would change the APT28 attribution assessment without automatically changing the defensive controls.

09

What to watch next

Weak

Watch for any webhook.site connection from a network or host with no business need and block or investigate it.

Prioritize hosts where macro-enabled Word activity is followed by batch/VBS execution, scheduled-task creation, and Microsoft Edge webhook traffic; review the full chain when that trigger appears.

Watch for publication of the primary campaign report or supporting telemetry and use it to validate and tune the sequence. Revise attribution only if direct operator-identity or state-tasking evidence appears.

Sources & context

Evidence basis

2 references
Context
Interaction
Observed 10 Sept 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 10 Sep 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.