logo

Renewed APT29 Phishing Campaign Against European Diplomats

ID: bb35bd13-9ac0-518c-aafa-1d63978b24df

STIX ID: report--bb35bd13-9ac0-518c-aafa-1d63978b24df

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2025-04-15

Date Updated: 2026-04-27

Author: [email protected]

...
...

Starting in January 2025, Check Point Research tracked a targeted phishing campaign attributed to APT29 that impersonates a European Ministry of Foreign Affairs to send wine-tasting invitations to diplomats and ministries across Europe. The attack uses malicious archives (wine.zip) that side-load a PowerPoint executable and two DLLs: a junk dependency (AppvIsvSubsystems64.dll) and a heavily obfuscated loader (ppcore.dll, "GRAPELOADER") which fingerprints hosts, establishes persistence via a Run registry key, and retrieves in-memory shellcode from C2 (ophibre.com); a new WINELOADER variant (vmtools.dll) appears to be deployed in later stages. The report details advanced anti-analysis techniques (string obfuscation, DLL unhooking, RC4-based unpacking), network IOCs (ophibre.com, bravecup.com, silry.com, bakenhof.com), file hashes for the archive and DLLs, and recommended protections from Check Point products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.