Description
Wineloader is a malware loader associated with the APT29 intrusion set, documented in phishing campaigns against European diplomats. Mandiant reported its use against German political parties in 2024, and researchers connected the campaigns to related tooling such as SPIKEDWINE and GrapeLoader. National authorities including France's ANSSI tied the activity to the broader Nobelium intrusion set.
Stats
- First seen
- April 2024
- Last seen
- September 2026
Alert name variants
| Alert Name |
|---|
| Document-HTML.Trojan.Wineloader |
| Win64.Backdoor.Wineloader |