GRAPELOADER is a malware loader associated with APT29 (also tracked as Cozy Bear and Midnight Blizzard), a Russian state-sponsored espionage group linked in the content to the SVR. It has been described as a newly observed initial-stage tool used for fingerprinting, persistence, and payload delivery, and as a loader capable of downloading and retrieving next-stage payloads. The reported delivery method is spearphishing, specifically phishing emails impersonating diplomatic or foreign affairs event invitations, including wine-tasting themed lures, that direct targets to booby-trapped ZIP archives. The infection chain described in the content uses DLL sideloading: a ZIP archive contains a legitimate PowerPoint launcher named wine.exe that side-loads a malicious DLL implementing GRAPELOADER. The malware is characterized in the content as stealthier than previous APT29 loaders, using DLL sideloading, advanced obfuscation, memory-protection techniques, and in-memory execution to evade detection. The campaign was reported as targeting European embassies and other European diplomatic entities. The content also states that APT29 has deployed GRAPELOADER alongside other loaders such as ROOTSAW and WINELOADER, with WINELOADER likely used in later stages of the campaign. No specific GRAPELOADER file hashes, domains, IPs, or other concrete IOCs are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
wine.exe + side-loaded malicious .dll (GRAPELOADER) Process/ DLL Zip contains genuine PowerPoint launcher (wine.exe) that side loads DLL implementing Grapeloader.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader referenced as used by APT29 in invitation-themed phishing campaigns.
Newly observed initial-stage malware loader used by APT29 in phishing campaigns targeting European diplomats.
Loader malware used by APT29 in spearphishing campaigns to deliver additional payloads.
Newly reported malware loader used by APT29 to download and execute next-stage payloads in phishing attacks against European diplomatic entities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.