#Headlace
January 15, 2026 at 5:41 PM
Overheard in the Discord:

"We can't not have Mill!"
"We have Mill at home!"

<the Mill we have at home>
February 20, 2026 at 10:12 PM
I HAVE MADE

THREE

Designs for what I think a Black Cherry Cookie could look like based on what I looked up (and last one is just me lol)

Based on a black forest cherry cookie, a black cherry cup cookie, and then me as a cookie :3 maybe call it cherry mochi cookie hehehe
August 4, 2025 at 6:10 AM

APT28, a Russian threat actor, is using Israel-Hamas war-related lures to distribute the HeadLace backdoor. This targeted campaign affects 13 nations globally.
thehackernews.com/2023/12/russ...
#cybersecurity #hacking #infosec
Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign
APT28, the Russian nation-state threat actor, is using lures related to the Israel-Hamas war to distribute the HeadLace backdoor.
thehackernews.com
December 12, 2023 at 8:56 PM
Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting #cybersecurity #infosec #privacy #news thehackernews.com/20...
May 31, 2024 at 11:06 AM
APT28 Targets Diplomats with HeadLace Malware via Car Sale Phishing Lure #cybersecurity #infosec #privacy #news thehackernews.com/20...
August 2, 2024 at 11:59 PM
Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign
Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign
APT28, the Russian nation-state threat actor, is using lures related to the Israel-Hamas war to distribute the HeadLace backdoor.
thehackernews.com
December 12, 2023 at 3:21 PM
Colleagues of mine just published a report on the evolution of GRU's BlueDelta operational infrastructure targeting networks across Europe with information-stealing Headlace malware and credential-harvesting web pages: www.recordedfuture.com/grus-bluedel...
GRU's BlueDelta Targets Key Networks in Europe with Multi-Phase Espionage Camp | Recorded Future
Discover BlueDelta’s (APT28, FANCY BEAR, Forest Blizzard) strategic espionage tactics in Europe. Learn more.
www.recordedfuture.com
May 31, 2024 at 10:02 PM
APT28's HOOKEDGE hides C2 traffic inside headless Microsoft Edge requests to webhook.site. https://intel.threadlinqs.com/threat/TL-2026-2213 #ThreatIntel #HOOKEDGE #Headlace #SOURFACE
August 29, 2026 at 6:34 PM
APT28's new backdoor has zero compiled code - it lives entirely in Word macros and a hidden Edge browser. https://intel.threadlinqs.com/threat/TL-2026-2187 #ThreatIntel #HOOKEDGE #Headlace #Operation
August 28, 2026 at 6:27 PM
BlueDelta Refines HEADLACE: HOOKEDGE Backdoor Abuses Legitimate Webhook Services
BlueDelta Refines HEADLACE: HOOKEDGE Backdoor Abuses Legitimate Webhook Services
The BlueDelta group has used macro-laced Word documents to distribute HOOKEDGE, a batch-script backdoor that leverages webhook.site for command and control. Campaigns have been active since September 2025.
deafnews.it
August 28, 2026 at 9:10 AM
BlueDelta's HOOKEDGE backdoor hides GRU C2 inside webhook.site traffic and a hidden Edge browser window. https://intel.threadlinqs.com/threat/TL-2026-2173 #ThreatIntel #HOOKEDGE #Headlace #msedgeexe
August 27, 2026 at 2:28 PM
GRU hackers hijacked border cameras to track Ukraine aid shipments then sent agents to stalk CEOs. https://intel.threadlinqs.com/threat/TL-2026-2031 #ThreatIntel #CVE_2023_23397 #CVE_2023_38831 #Headlace
August 16, 2026 at 5:34 PM
Russia's 'Fighting Ursa' APT Uses Car Ads to Install HeadLace Malware
Russia's 'Fighting Ursa' APT Uses Car Ads to Install HeadLace Malware
The scheme from the group also known as APT28 involves targeting Eastern European diplomats in need of personal transportation, tempting them with a purported good deal on a Audi Q7 Quattro SUV.
www.darkreading.com
August 5, 2024 at 12:06 PM
Russia-linked APT used a car for sale as a phishing lure to target diplomats with HeadLace malware
Russia-linked APT used a car for sale as a phishing lure to target diplomats with HeadLace malware
A Russia-linked APT used a car for sale as a phishing lure to deliver a modular Windows backdoor called HeadLace.
securityaffairs.com
August 3, 2024 at 3:35 PM
APT28 Targets Diplomats with HeadLace Malware via Car Sale Phishing Lure
APT28 Targets Diplomats with HeadLace Malware via Car Sale Phishing Lure
A Russia-linked threat actor, APT28, is using a car-for-sale phishing lure to deliver a new Windows backdoor called HeadLace.
thehackernews.com
August 2, 2024 at 4:55 PM
APT28 targets key networks in Europe with HeadLace malware
APT28 targets key networks in Europe with HeadLace malware
Russia-linked APT28 used the HeadLace malware and credential-harvesting web pages in attacks against networks across Europe.
securityaffairs.com
June 3, 2024 at 10:29 AM
Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting
Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting
Russian GRU-backed threat actor APT28 is behind campaigns targeting networks across Europe with HeadLace malware and credential-harvesting web pages.
thehackernews.com
May 31, 2024 at 11:03 AM
#100DaysofYARA Day 8 - fun with the scriptlets dropped by APT28/TA422/FancyBear

we call it EchoLaunch, @XForceGlobal calls this HeadLace - check out their excellent work:...
November 29, 2024 at 6:14 PM