Skip to content

GRAPELOADER

GRAPELOADER is a malware loader associated with APT29 (also tracked as Cozy Bear and Midnight Blizzard), a Russian state-sponsored espionage group linked in the content to the SVR.

Profile source: Mallory opens in a new tab

GRAPELOADER

Family profile

GRAPELOADER is a malware loader associated with APT29 (also tracked as Cozy Bear and Midnight Blizzard), a Russian state-sponsored espionage group linked in the content to the SVR. It has been described as a newly observed initial-stage tool used for fingerprinting, persistence, and payload delivery, and as a loader capable of downloading and retrieving next-stage payloads. The reported delivery method is spearphishing, specifically phishing emails impersonating diplomatic or foreign affairs event invitations, including wine-tasting themed lures, that direct targets to booby-trapped ZIP archives. The infection chain described in the content uses DLL sideloading: a ZIP archive contains a legitimate PowerPoint launcher named wine.exe that side-loads a malicious DLL implementing GRAPELOADER. The malware is characterized in the content as stealthier than previous APT29 loaders, using DLL sideloading, advanced obfuscation, memory-protection techniques, and in-memory execution to evade detection. The campaign was reported as targeting European embassies and other European diplomatic entities. The content also states that APT29 has deployed GRAPELOADER alongside other loaders such as ROOTSAW and WINELOADER, with WINELOADER likely used in later stages of the campaign. No specific GRAPELOADER file hashes, domains, IPs, or other concrete IOCs are provided in the content.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 14, 2026
Last activity
Sep 14, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • FR1

Leading providers

  • Regxa Company for Information Technology Ltd1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
APT29

wine.exe + side-loaded malicious .dll (GRAPELOADER) Process/ DLL Zip contains genuine PowerPoint launcher (wine.exe) that side loads DLL implementing Grapeloader.

MITRE ATT&CK

GRAPELOADER in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.