Last seven days
- First activity
- Sep 14, 2026
- Last activity
- Sep 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
GRAPELOADER is a malware loader associated with APT29 (also tracked as Cozy Bear and Midnight Blizzard), a Russian state-sponsored espionage group linked in the content to the SVR.
Profile source: Mallory opens in a new tabGRAPELOADER
GRAPELOADER is a malware loader associated with APT29 (also tracked as Cozy Bear and Midnight Blizzard), a Russian state-sponsored espionage group linked in the content to the SVR. It has been described as a newly observed initial-stage tool used for fingerprinting, persistence, and payload delivery, and as a loader capable of downloading and retrieving next-stage payloads. The reported delivery method is spearphishing, specifically phishing emails impersonating diplomatic or foreign affairs event invitations, including wine-tasting themed lures, that direct targets to booby-trapped ZIP archives. The infection chain described in the content uses DLL sideloading: a ZIP archive contains a legitimate PowerPoint launcher named wine.exe that side-loads a malicious DLL implementing GRAPELOADER. The malware is characterized in the content as stealthier than previous APT29 loaders, using DLL sideloading, advanced obfuscation, memory-protection techniques, and in-memory execution to evade detection. The campaign was reported as targeting European embassies and other European diplomatic entities. The content also states that APT29 has deployed GRAPELOADER alongside other loaders such as ROOTSAW and WINELOADER, with WINELOADER likely used in later stages of the campaign. No specific GRAPELOADER file hashes, domains, IPs, or other concrete IOCs are provided in the content.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
wine.exe + side-loaded malicious .dll (GRAPELOADER) Process/ DLL Zip contains genuine PowerPoint launcher (wine.exe) that side loads DLL implementing Grapeloader.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.