• News/
  • https://www.theregister.com/2024/03/23/russia_cozy_bear_german_politicians_phishing/

Russia's Cozy Bear caught phishing German politicos with phony dinner invites

The Register
·
Jessica Lyons
·
Published Mar 23, 2024
·
Updated

The Kremlin's cyberspies targeted German political parties in a phishing campaign that used emails disguised as dinner party invitations, according to Mandiant. Russia's Cozy Bear, also known as APT29 and Midnight Blizzard, engineered the messages to infect marks' Windows PCs with a backdoor first observed in January and dubbed WINELOADER. These were intended to provide long-term access to the political parties' networks and data, the Google-backed security biz asserted on Friday. This is the first time that the cyberespionage group, which has been linked to the Russian Foreign Intelligence Service (SVR), has targeted political parties, according to the report. "Western political parties and their associated bodies from across the political spectrum are likely also possible targets for future SVR-linked cyber espionage activity given Moscow's vital interest in understanding changing Western political dynamics related to Ukraine and other flashpoint foreign policy issues," Mandiant's Luke Jenkins and Dan Black wrote in an alert. This is the same crew that infamously backdoored SolarWinds' network monitoring software and then used that access to spy on customers such as the US Treasury, Justice, and Energy departments, and the Pentagon. Cozy Bear's latest phishing emails, sent out last month, were designed to give to the impression they were sent by Germany's Christian Democratic Union (CDU), and included the major political party's logo, inviting recipients to a March 1 dinner...

Read full article

Affected Software

2 affected components
Microsoft Windows
SolarWinds network monitoring software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a phishing campaign conducted by Russia's Cozy Bear targeting German politicians using fake dinner invitations.

2

What security implications are discussed?

The article highlights the threat posed by state-sponsored hacking groups like Cozy Bear and their use of social engineering tactics in cyberattacks.

3

Who is Cozy Bear and what are they known for?

Cozy Bear, also known as APT29 or Midnight Blizzard, is a Russian cyber espionage group linked to the Kremlin.

4

What methods were used in the phishing campaign?

The campaign primarily utilized emails disguised as dinner party invitations to deceive recipients.

5

What products or software are affected by this phishing campaign?

The phishing campaign mentioned affects users of Microsoft Windows and SolarWinds network monitoring software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203