HELLFIRE https://www.theregister.com/2025/04/16/cozy_bear_grapeloader/ Russia never stops using proven tactics, and its Cozy Bear, aka APT 29, cyber-spies are once again trying to lure European diplomats into downloading malware with a phony invitation to a lux event. Last year, the Kremlin team went after German politicians with Windows backdoor malware dubbed Wineloader concealed in fake invitations to a dinner reception. Now, malware hunters at Check Point say the same crew is back with Grapeloader, and instead of supper, the Russians are luring Euro diplomats with an invitation to wine tasting. Offers to attend the swish gathering arrive in an email disguised to resemble a missive from an unnamed European country’s Ministry of Foreign Affairs and were sent to diplomats across the continent. If the targets failed to respond, the scammers sent follow up emails. Subject lines included “Wine tasting event (update date),” “For Ambassador’s Calendar,” and “Diplomatic dinner.” The message itself has a link to a download from a remote server that really shouldn’t be clicked on. … Sharing from a free reeducation safe hex POV. Regards
egeezer Ah yes, an unsolicited email with a click bait link to follow. I don’t even follow links from my bank’s marketing emails.