logo

New Backdoor Targeting European Officials Linked to Indian Diplomatic Events

ID: e4977736-8424-5b49-81f7-e12e212747d1

STIX ID: report--e4977736-8424-5b49-81f7-e12e212747d1

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-02-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Zscaler ThreatLabz observed a low-volume, targeted cyber-espionage campaign by a previously undocumented actor named SPIKEDWINE that used malicious PDFs and an HTA to deliver a new backdoor, WINELOADER, to European diplomatic staff; the malware is modular, supports C2-driven module execution and DLL injection, and the campaign uses compromised websites and timing/evasion techniques to avoid detection, with multiple samples and hosting artifacts linked via VirusTotal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.