Renewed APT29 Phishing Campaign Against European Diplomats
ID: bb35bd13-9ac0-518c-aafa-1d63978b24df
STIX ID: report--bb35bd13-9ac0-518c-aafa-1d63978b24df
Feed Name: Check Point Research
Starting in January 2025, Check Point Research tracked a targeted phishing campaign attributed to APT29 that impersonates a European Ministry of Foreign Affairs to send wine-tasting invitations to diplomats and ministries across Europe. The attack uses malicious archives (wine.zip) that side-load a PowerPoint executable and two DLLs: a junk dependency (AppvIsvSubsystems64.dll) and a heavily obfuscated loader (ppcore.dll, "GRAPELOADER") which fingerprints hosts, establishes persistence via a Run registry key, and retrieves in-memory shellcode from C2 (ophibre.com); a new WINELOADER variant (vmtools.dll) appears to be deployed in later stages. The report details advanced anti-analysis techniques (string obfuscation, DLL unhooking, RC4-based unpacking), network IOCs (ophibre.com, bravecup.com, silry.com, bakenhof.com), file hashes for the archive and DLLs, and recommended protections from Check Point products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
