APT29, a Russian state-sponsored threat actor, has been connected to a sophisticated phishing campaign that uses a new version of WINELOADER and a hitherto undiscovered malware loader called GRAPELOADER to target diplomatic institutions around Europe.
According to a technical analysis released earlier this week by Check Point, GRAPELOADER is a recently discovered initial-stage tool used for fingerprinting, persistence, and payload delivery, whilst the enhanced WINELOADER variation is still a modular backdoor used in later stages.
Both are comparable in terms of code structure, obfuscation, and string decryption, but having different functions. GRAPELOADER introduces more sophisticated stealth mechanisms while improving upon WINELOADER’s anti-analysis features.
Zscaler ThreatLabz initially reported on the deployment of WINELOADER in February 2024 read more about APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through Wine Tasting Lures.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
