PULSE NAME
Renewed APT29 Phishing Campaign Against European Diplomats
WHITE APT29 AlienVault 2025-04-15 Modified: 2025-04-15
21
IOCs
MEDIUM VOLUME
A sophisticated phishing campaign targeting European diplomatic entities has been uncovered, attributed to the Russia-linked threat group APT29. The attackers impersonate a major European foreign affairs ministry, sending fake invitations to wine tasting events. The campaign employs a new loader called GRAPELOADER, which is used for initial reconnaissance and payload delivery. Additionally, a new variant of the WINELOADER backdoor has been discovered, likely used in later stages of the attack. Both malware components share similarities in code structure and obfuscation techniques. The campaign focuses on European diplomatic targets, including non-European embassies in Europe, with some indications of limited targeting outside the region.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GRAPELOADER WINELOADER
Indicators of Compromise (21)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a89b9bdf5f28f4380f383ee199401bdc 2025-04-15
FileHash-MD5 e025fa8354968f298af3f6ef2f22d7d3 2025-04-15
FileHash-MD5 e06fbace9c2297e47e6bf991f2681b2b 2025-04-15
FileHash-MD5 f474f6cd156e53a994ae3d25dcecb50c 2025-04-15
FileHash-SHA1 3a7b4a507db8ac2aa59c83a59dcf1242411d14f5 2025-04-15
FileHash-SHA1 56248469a7c079c4174f6c8351b48294bd7a57e0 2025-04-15
FileHash-SHA1 5a3bd2f12875098bd06b9f5a5a9405d9cf3af837 2025-04-15
FileHash-SHA1 b4221c83a3fffe7bc358dfc613c3e58fcc522a23 2025-04-15
FileHash-SHA256 24c079b24851a5cc8f61565176bbf1157b9d5559c642e31139ab8d76bbb320f8 2025-04-15
FileHash-SHA256 420d20cddfaada4e96824a9184ac695800764961bad7654a6a6c3fe9b1b74b9a 2025-04-15
FileHash-SHA256 653db3b63bb0e8c2db675cd047b737cefebb1c955bd99e7a93899e2144d34358 2025-04-15
FileHash-SHA256 78a810e47e288a6aff7ffbaf1f20144d2b317a1618bba840d42405cddc4cff41 2025-04-15
FileHash-SHA256 85484716a369b0bc2391b5f20cf11e4bd65497a34e7a275532b729573d6ef15e 2025-04-15
FileHash-SHA256 adfe0ef4ef181c4b19437100153e9fe7aed119f5049e5489a36692757460b9f8 2025-04-15
FileHash-SHA256 d931078b63d94726d4be5dc1a00324275b53b935b77d3eed1712461f0c180164 2025-04-15
URL https://bakenhof.com/invb.php 2025-04-15
URL https://silry.com/inva.php 2025-04-15
domain bakenhof.com 2025-04-15
domain bravecup.com 2025-04-15
domain ophibre.com 2025-04-15
domain silry.com 2025-04-15