Wine Not? Cozy Bear’s Phishy Invitations Uncork Cyber Espionage Drama!

Midnight Blizzard, aka APT29 or Cozy Bear, is targeting European embassies with phishing emails disguised as wine tasting invites. These emails contain GrapeLoader malware that leads to the sneakier WineLoader backdoor. So, next time you get a wine tasting invite, remember: it’s not always a merlot, sometimes it’s malware!

Pro Dashboard

Hot Take:

Forget the grapes of wrath; now we have the grapes of attack! Midnight Blizzard seems to have an unparalleled love for wine-tasting parties — or at least for using them as a cover to infiltrate the digital cellars of European diplomats. While some folks are busy swirling wine glasses, others are busy swirling around malware. Cheers to cyber espionage, where the wine isn’t the only thing with legs!

Key Points:

  • Midnight Blizzard (APT29/Cozy Bear) targets European embassies with phishing emails disguised as wine-tasting invitations.
  • The campaign involves new malware called GrapeLoader and an updated version of WineLoader backdoor.
  • Emails are sent from two websites, leading to a file download that executes the malware.
  • GrapeLoader ensures persistent access by altering computer settings and avoiding detection.
  • WineLoader gathers sensitive information and is harder to detect than its predecessors.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?