• News/
  • https://www.bleepingcomputer.com/news/security/russian-hackers-target-german-political-parties-with-wineloader-malware/

Russian hackers target German political parties with WineLoader malware

BleepingComputer
·
Bill Toulas
·
Published Mar 22, 2024
·
Updated

Researchers are warning that a notorious hacking group linked to Russia's Foreign Intelligence Service (SVR) is targeting political parties in Germany for the first time, shifting their focus away from the typical targeting of diplomatic missions. The phishing attacks are designed to deploy a backdoor malware named WineLoader, which allows threat actors to gain remote access to compromised devices and networks. APT29 (also known as Midnight Blizzard, NOBELIUM, Cozy Bear) is a Russian espionage hacking group believed to be part of the Russian Foreign Intelligence Service (SVR) The hacking group has been linked to many cyberattacks, including the infamous SolarWinds supply chain attack in December 2020. The threat actors have remained active throughout these years, typically targeting governments, embassies, senior officials, and various entities using a range of phishing tactics or supply chain compromises. APT29's recent focus has been on cloud services, breaching Microsoft systems and stealing data from Exchange accounts, and compromising the MS Office 365 email environment used by Hewlett Packard Enterprise. Mandiant researchers say that APT29 has been conducting a phishing campaign against German political parties since late February 2024. This marks a significant shift in the hacking group's operational focus, as it's the first time the hacking group has targeted political parties. The hackers now use phishing emails with a lure themed around the Christian Democratic Uni...

Read full article

Affected Software

3 affected components
Microsoft Exchange
Microsoft Office 365
Hewlett Packard Enterprise Email Environment
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Russian hackers targeting German political parties using WineLoader malware.

2

What security implications are discussed in the article?

The article highlights concerns over the potential compromise of sensitive political information and the implications for national security.

3

What hacking group is linked to the attacks mentioned in the article?

The hacking group is associated with Russia's Foreign Intelligence Service (SVR).

4

What products or software are affected by the WineLoader malware?

The affected software includes Microsoft Exchange, Microsoft Office 365, and Hewlett Packard Enterprise Email Environment.

5

Why is the targeting of German political parties significant?

This marks the first time such attacks have focused on German political parties, signaling a shift in the hackers' strategies.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203