Russia-linked hackers targeting European diplomats with invites to bogus wine tasting events
Share and Follow

A Russia-linked hacking group unleashed a new “advanced phishing campaign” targeting European diplomats with invites to fake wine tasting events, according to a report. 

Check Point Research said the APT29 group is trying to “impersonate a major European Ministry of Foreign Affairs to send out invitations to wine tasting events, prompting targets to click a web link leading to the deployment of a new backdoor [malware] called GRAPELOADER.”  

“This campaign appears to be focused on targeting European diplomatic entities, including non-European countries’ embassies located in Europe,” the cybersecurity firm said in an advisory, noting that the emails with malicious links included subject lines such as “Wine tasting event (update date),” “For Ambassador’s Calendar” and “Diplomatic dinner.” 

The U.S. Cybersecurity and Infrastructure Security Agency said last year that APT29, which also goes by the names of Midnight Blizzard, the Dukes, or Cozy Bear, is “a cyber espionage group, almost certainly part of the SVR, an element of the Russian intelligence services.” 

Person drinks a glass of wine

Check Point Research said the APT29 group is trying to “impersonate a major European foreign affairs ministry to distribute fake invitations to diplomatic events – most commonly, wine tasting events.” (Justin Sullivan/Getty Images)

“In cases where the initial attempt was unsuccessful, additional waves of emails were sent to increase the likelihood of getting the victim to click the link and compromise his machine,” it added. 

“The server hosting the link is believed to be highly protected against scanning and automated analysis solutions, with the malicious download triggered only under certain conditions, such as specific times or geographic locations. When accessed directly, the link redirects to the official website of the impersonated Ministry of Foreign Affairs,” the firm continued. 

Two glasses of red wine rest on a barrel next to grapes.

The malacious emails had subject lines including “Wine Event,” according to Check Point Research. (iStock)

It is unclear if any of the phishing attacks were successful. 

Share and Follow
You May Also Like
Gene Hackman's $6M Santa Fe mansion is snapped up

Luxury Living: Discover the $6M Santa Fe Mansion Once Owned by Legendary Actor Gene Hackman

Gene Hackman’s Santa Fe estate is on the verge of being sold,…
Judge orders ICE chief to appear in court to explain why detainees have been denied due process

Court Summons ICE Chief to Address Alleged Due Process Violations for Detainees

MINNEAPOLIS, Minn. — In a significant development, Minnesota’s chief federal judge has…
The high-speed chase ended with the teen crashing the SUV.

Missing Teen in Stolen SUV Survives High-Speed Chase and Rollover Crash After Crossing Into Oncoming Traffic

Dashcam footage has captured a dramatic scene where a 17-year-old behind the…
Surgeon stalked ex-wife weeks before killing her and new spouse

Tragic End: Surgeon Stalks and Murders Ex-Wife and Her New Husband After Weeks of Harassment

A surgeon currently facing serious accusations of double murder for allegedly taking…
Dozens arrested after protesters take over NYC hotel lobby during anti-ICE demonstration

Mass Arrests at NYC Hotel: Anti-ICE Protest Shakes the City!

Authorities made several arrests following a protest against ICE that erupted inside…
Omar approached at town hall and sprayed with unknown substance

Omar Targeted with Unknown Substance at Town Hall Meeting

During a town hall meeting in her district on Tuesday, Representative Ilhan…
Kendall Jenner takes SAVAGE swipe at NBA exes in first Superbowl ad

Kendall Jenner Delivers Bold Message to NBA Exes in Debut Super Bowl Advertisement

Kendall Jenner recently embraced the long-standing joke about her ‘cursed’ love life…
Vandals cover California's Yosemite National Park in graffiti

Graffiti Vandalism Strikes California’s Iconic Yosemite National Park

A recent act of vandalism at Yosemite National Park has left visitors…