Wave of Wine-Inspired Phishing Attacks Targets EU Diplomats
ID: 04be5fc9-7128-5817-94aa-a35676fac6b7
STIX ID: report--04be5fc9-7128-5817-94aa-a35676fac6b7
Feed Name: Dark Reading
Date Published: 2025-04-15
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Check Point Research observed an APT29 phishing campaign impersonating a European Ministry of Foreign Affairs that lures diplomats with wine‑tasting invitations. Clicking malicious links downloads a wine.zip bundle containing a PowerPoint executable used for DLL side‑loading and a heavily obfuscated loader (ppcore.dll) that deploys a new backdoor dubbed GrapeLoader (with a later-stage WineLoader variant); the malware establishes persistence via the Windows Run key, collects basic host information, and waits for C2-delivered shellcode while the attacker employs anti-analysis and geo/time activation controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
