logo

Russia's Cozy Bear caught phishing German politicos with phony dinner invites

ID: a885781b-0247-50b2-894e-ed76aab5573a

STIX ID: report--a885781b-0247-50b2-894e-ed76aab5573a

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-03-23

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Mandiant reports that Russian-linked APT29 (Cozy Bear) conducted a phishing campaign targeting German political parties using spoofed dinner invitations that led victims to download a ZIP containing ROOTSAW, which installs the WINELOADER backdoor from attacker-controlled domains; WINELOADER has been observed previously against diplomats and is a customized loader enabling long-term remote access and C2 communications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.