logo

German political party targeted by SVR-linked group in spearphishing campaign, Mandiant says

ID: 6800409a-26ab-57fd-aa67-8c6d59d371a8

STIX ID: report--6800409a-26ab-57fd-aa67-8c6d59d371a8

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2024-03-22

Date Updated: 2026-04-21

Author: djohnson

...
...

Mandiant discovered a late-February APT29 (SVR/Cozy Bear) spearphishing campaign targeting German political parties using a spoofed CDU invitation that redirected victims to a compromised WordPress site delivering a ROOTSAW dropper and the WINELOADER backdoor; the reporting links this activity to prior SVR operations (including SolarWinds) and warns of wider espionage risks and cloud/service-account access attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.