logo

Russian Hackers Use 'WINELOADER' Malware to Target German Political Parties

ID: 5acc7095-30d7-5a61-8b4a-321e399ece88

STIX ID: report--5acc7095-30d7-5a61-8b4a-321e399ece88

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-03-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mandiant and Zscaler attribute a multi-stage espionage campaign, ongoing since at least July 2023, to APT29 (SVR-linked). Attackers used German-language wine-tasting phishing lures that deliver an HTA ROOTSAW dropper and deploy the WINELOADER backdoor via DLL side-loading (sqldumper.exe) to target diplomatic entities and German political parties across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.