PULSE NAME
Renewed APT29 Phishing Campaign Against European Diplomats
WHITE APT29 AlienVault 2025-04-15 Modified: 2025-04-15
21
IOCs
MEDIUM VOLUME
A sophisticated phishing campaign targeting European diplomatic entities has been uncovered, attributed to the Russia-linked threat group APT29. The attackers impersonate a major European foreign affairs ministry, sending fake invitations to wine tasting events. The campaign employs a new loader called GRAPELOADER, which is used for initial reconnaissance and payload delivery. Additionally, a new variant of the WINELOADER backdoor has been discovered, likely used in later stages of the attack. Both malware components share similarities in code structure and obfuscation techniques. The campaign focuses on European diplomatic targets, including non-European embassies in Europe, with some indications of limited targeting outside the region.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GRAPELOADER WINELOADER
Indicators of Compromise (7 / 21 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 24c079b24851a5cc8f61565176bbf1157b9d5559c642e31139ab8d76bbb320f8 2025-04-15
FileHash-SHA256 420d20cddfaada4e96824a9184ac695800764961bad7654a6a6c3fe9b1b74b9a 2025-04-15
FileHash-SHA256 653db3b63bb0e8c2db675cd047b737cefebb1c955bd99e7a93899e2144d34358 2025-04-15
FileHash-SHA256 78a810e47e288a6aff7ffbaf1f20144d2b317a1618bba840d42405cddc4cff41 2025-04-15
FileHash-SHA256 85484716a369b0bc2391b5f20cf11e4bd65497a34e7a275532b729573d6ef15e 2025-04-15
FileHash-SHA256 adfe0ef4ef181c4b19437100153e9fe7aed119f5049e5489a36692757460b9f8 2025-04-15
FileHash-SHA256 d931078b63d94726d4be5dc1a00324275b53b935b77d3eed1712461f0c180164 2025-04-15