Russia-linked APT29 targets European diplomatic entities with GRAPELOADER

Russia-linked group APT29 targeted diplomatic entities across Europe with a new malware loader codenamed GRAPELOADER.

Security Affairs

Good day everyone!

Check Point Software researchers produced another great article that involves #APT29 and #phishing and a little bit of masquerading. This phishing campaign targeted European diplomatic entities that distributes fake invitations to diplomatic events and appears to be a continuation of a previous campaign run by the same actors. These phishing emails utilized a backdoor known as #Wineloader and also employs a new loader #Grapeloader. There is a lot to unpack here and I hope you enjoy!

Renewed APT29 Phishing Campaign Against European Diplomats
https://research.checkpoint.com/2025/apt29-phishing-campaign/

Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

Renewed APT29 Phishing Campaign Against European Diplomats - Check Point Research

Check Point Research uncovers APT29 targeting European diplomatic entities with phishing attacks spreading malware Grapeloader

Check Point Research

A wine tasting invite that turns into a covert cyber strike? Russian hackers are targeting European diplomats with a malware hidden in a seemingly harmless "wine.zip." Find out how GrapeLoader slips past security.

https://thedefendopsdiaries.com/grapeloader-malware-a-new-cyber-espionage-threat/

#grapeloader
#cyberespionage
#midnightblizzard
#spearphishing
#cybersecurity