APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through Wine-Tasting Lures
APT29, a Russian state-sponsored threat actor, has been connected to a sophisticated phishing campaign that uses a new version of WINELOADER and a hitherto undiscovered malware loader called GRAPELOADER to target diplomatic institutions around Europe.
According to a technical analysis released earlier this week by Check Point, GRAPELOADER is a recently discovered initial-stage tool used for fingerprinting, persistence, and payload delivery, whilst the enhanced WINELOADER variation is still a modular backdoor used in later stages.
Both are comparable in terms of code structure, obfuscation, and string decryption, but having different functions. GRAPELOADER introduces more sophisticated stealth mechanisms while improving upon WINELOADER's anti-analysis features.
Zscaler ThreatLabz ...


