216.73.216.6

Renewed APT29 Phishing Campaign Against European Diplomats

· Published 15/04/2025 18:49 · Modified 15/04/2025 19:19

Export JSON

Essential information

Published
15/04/2025 18:49
Modified
15/04/2025 19:19
Tags
2025-04-15 backdoor grapeloader phishing wineloader
Related entities
13 observables, 1 intrusion sets (apt), 3 techniques (mitre), 2 malware, 11 others

Description

A sophisticated campaign targeting European diplomatic entities has been uncovered, attributed to the Russia-linked threat group APT29. The attackers impersonate a major European foreign affairs ministry, sending fake invitations to wine tasting events. The campaign employs a new loader called , which is used for initial reconnaissance and payload delivery. Additionally, a new variant of the has been discovered, likely used in later stages of the attack. Both malware components share similarities in code structure and obfuscation techniques. The campaign focuses on European diplomatic targets, including non-European embassies in Europe, with some indications of limited targeting outside the region.

External references