logo

Russian hackers target German political parties with WineLoader malware

ID: 66669ad9-5d63-52bf-bcd6-bcfb3f60435d

STIX ID: report--66669ad9-5d63-52bf-bcd6-bcfb3f60435d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-03-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers report that APT29 (aka NOBELIUM/Cozy Bear) has shifted to targeting German political parties with phishing lures impersonating the CDU; the attacks deliver a Rootsaw dropper that installs the modular WineLoader backdoor (RC4-decrypted, DLL side-loading via sqldumper.exe) enabling encrypted C2 communications and dynamic module execution for espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.