logo

Wave of Wine-Inspired Phishing Attacks Targets EU Diplomats

ID: 04be5fc9-7128-5817-94aa-a35676fac6b7

STIX ID: report--04be5fc9-7128-5817-94aa-a35676fac6b7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-04-15

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Check Point Research observed an APT29 phishing campaign impersonating a European Ministry of Foreign Affairs that lures diplomats with wine‑tasting invitations. Clicking malicious links downloads a wine.zip bundle containing a PowerPoint executable used for DLL side‑loading and a heavily obfuscated loader (ppcore.dll) that deploys a new backdoor dubbed GrapeLoader (with a later-stage WineLoader variant); the malware establishes persistence via the Windows Run key, collects basic host information, and waits for C2-delivered shellcode while the attacker employs anti-analysis and geo/time activation controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.