WINELOADER is a modular Windows backdoor associated with APT29, the Russian state-linked espionage group also tracked as Cozy Bear and Midnight Blizzard. It has been used in targeted cyber-espionage campaigns against diplomatic entities in Europe and against German political organizations, including operations using diplomatic- and political-themed lures. The malware is assessed to support intelligence collection objectives aligned with Russian foreign intelligence interests.
WINELOADER is typically deployed as a later-stage payload in multi-step intrusion chains. Reported delivery activity includes spearphishing and phishing lures that direct victims to compromised or actor-controlled landing pages, followed by staged download and execution. In observed campaigns, loaders such as ROOTSAW and GRAPELOADER have been used to retrieve or execute WINELOADER. One documented chain used an obfuscated HTA stage, built-in Windows utilities for decoding and extraction, and abuse of a legitimate signed executable for DLL sideloading to launch a malicious DLL that decrypted and executed the WINELOADER core.
The malware is designed for stealth and persistence. It has been described as a backdoor capable of maintaining access in victim environments and facilitating theft of sensitive information. Observed functionality includes encrypted configuration and strings, encrypted command-and-control traffic, memory hygiene measures such as zeroing buffers after use, and process execution through DLL hollowing or related injection into legitimate Windows DLLs. Command handling supports execution of additional modules, reinjection, and beacon timing changes. A persistence component has been observed establishing scheduled-task or user-run-key persistence.
WINELOADER has also been linked to DLL sideloading tradecraft involving trusted Windows binaries, particularly in campaigns themed around diplomatic invitations. Reporting has further assessed it as likely related to the private BURNTBATTER and MUSKYBEAT code families tied to APT29. Overall, WINELOADER represents a tailored espionage backdoor used in precise, low-volume operations against high-value political and diplomatic targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Moreover, ANSSI and its partners observed several indicators of compromise (IOCs) linked to Nobelium’s latest campaigns. They are available on Zscaler and Mandiant websites.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Known Exploited Vulnerabilities ... CVE-2018-13379 ... CVE-2019-11510 ... CVE-2019-19781 ... CVE-2023-42793 ... ProxyLogon ... ProxyShell
Phishing (T1566): APT29 uses spearphishing emails with malicious links or attachments to gain initial access.
These campaigns leverage diplomatic-themed lures to initiate infection chains... The use of themed lures, such as invitations from the Ambassador of India and CDU-themed documents, highlights APT29's strategic use of social engineering to compromise targets.
2013 APT29 was attributed with targeting organizations by exploiting CVE-2013-0640 in Adobe Reader, the attacks involved the use of social engineering attacks for initial access.
APT29 was attributed with sending phishing emails purportedly from the USAID government agency that contained a malicious link that resulted in an ISO file being delivered. The file contained a malicious LNK file, a malicious DLL file, and a legitimate lure referencing foreign threats to the 2020 US Federal Elections.
The precision of these attacks, coupled with the use of compromised websites for command and control, underscores the evolving threat landscape...
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware used in a campaign targeting a German political party.
Loader referenced as used by APT29 in invitation-themed phishing campaigns.
WINELOADER is referenced in an associated analytic story, implying relevance to attacker tradecraft involving payload delivery or post-compromise activity.
Modular backdoor used in later stages of APT29 activity; referenced as improved variant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.