Russian hackers target German political parties with WineLoader malware
ID: 66669ad9-5d63-52bf-bcd6-bcfb3f60435d
STIX ID: report--66669ad9-5d63-52bf-bcd6-bcfb3f60435d
Feed Name: Bleeping Computer
Threat Score
Researchers report that APT29 (aka NOBELIUM/Cozy Bear) has shifted to targeting German political parties with phishing lures impersonating the CDU; the attacks deliver a Rootsaw dropper that installs the modular WineLoader backdoor (RC4-decrypted, DLL side-loading via sqldumper.exe) enabling encrypted C2 communications and dynamic module execution for espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
