216.73.217.22

WINELOADER Analysis

· Published 07/11/2024 22:48 · Modified 08/11/2024 10:22

Export JSON

Essential information

Published
07/11/2024 22:48
Modified
08/11/2024 10:22
Tags
2024-11-07 apt29 backdoor cozy bear diplomats dll hollowing dll side-loading evasion modular wineloader
Related entities
1 intrusion sets (apt), 1 malware, 3 others

Description

, also known as , has targeted European using a sophisticated multi-stage attack chain involving a new called . The attack begins with a fake PDF invitation to a wine-tasting event, which leads to the download of a malicious HTA file. This file then downloads and executes the , which uses advanced techniques such as , encryption, and . The malware communicates with command and control servers hosted on compromised websites, downloading additional modules and establishing persistence through scheduled tasks or registry keys. The campaign demonstrates 's focus on exploiting diplomatic relations between India and European nations, showcasing their advanced tactics and efforts to remain undetected.

External references