PULSE NAME
Renewed APT29 Phishing Campaign Against European Diplomats
WHITE APT29 AlienVault 2025-04-15 Modified: 2025-04-15
21
IOCs
MEDIUM VOLUME
A sophisticated phishing campaign targeting European diplomatic entities has been uncovered, attributed to the Russia-linked threat group APT29. The attackers impersonate a major European foreign affairs ministry, sending fake invitations to wine tasting events. The campaign employs a new loader called GRAPELOADER, which is used for initial reconnaissance and payload delivery. Additionally, a new variant of the WINELOADER backdoor has been discovered, likely used in later stages of the attack. Both malware components share similarities in code structure and obfuscation techniques. The campaign focuses on European diplomatic targets, including non-European embassies in Europe, with some indications of limited targeting outside the region.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GRAPELOADER WINELOADER
Indicators of Compromise (4 / 21 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a89b9bdf5f28f4380f383ee199401bdc 2025-04-15
FileHash-MD5 e025fa8354968f298af3f6ef2f22d7d3 2025-04-15
FileHash-MD5 e06fbace9c2297e47e6bf991f2681b2b 2025-04-15
FileHash-MD5 f474f6cd156e53a994ae3d25dcecb50c 2025-04-15