Tag: GrapeLoader malware

APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through Wine-Tasting Lures
News

APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through Wine-Tasting Lures

APT29, a Russian state-sponsored threat actor, has been connected to a sophisticated phishing campaign that uses a new version of WINELOADER and a hitherto undiscovered malware loader called GRAPELOADER to target diplomatic institutions around Europe. According to a technical analysis released earlier this week by Check Point, GRAPELOADER is a recently discovered initial-stage tool used for fingerprinting, persistence, and payload delivery, whilst the enhanced WINELOADER variation is still a modular backdoor used in later stages. Both are comparable in terms of code structure, obfuscation, and string decryption, but having different functions. GRAPELOADER introduces more sophisticated stealth mechanisms while improving upon WINELOADER's anti-analysis features. Zscaler ThreatLabz ...
Midnight Blizzard deploys new GrapeLoader malware in embassy phishing
News

Midnight Blizzard deploys new GrapeLoader malware in embassy phishing

A new spear-phishing attack targeting diplomatic institutions in Europe, including embassies, is being carried out by the Russian state-sponsored espionage group Midnight Blizzard. The state-sponsored cyberespionage outfit Midnight Blizzard, also known as "Cozy Bear" or "APT29," is associated with Russia's Foreign Intelligence Service (SVR). Check Point Research claims that the current campaign introduces a new version of the 'WineLoader' backdoor as well as a malware loader known as 'GrapeLoader,' which had not been seen before. The phishing campaign began in January 2025 and starts with an email invited to a wine tasting event from 'bakenhof[.]com' or'silry[.]com,' posing as a Ministry of Foreign Affairs. The malicious link in the email causes a ZIP archive read more about M...