The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →“Russia-linked APT29 uses new malware in embassy attacks” combines two separate campaigns. Check Point Research reported APT29’s GRAPELOADER and WINELOADER activity against European diplomatic targets. Microsoft separately reported that Secret Blizzard used ApolloShadow in a campaign targeting foreign embassies in Moscow. The actors, malware and reported access methods are different.
What the reports actually describe
The two reports concern diplomatic targeting, but they do not describe one operation or a shared malware chain. Check Point Research’s April 15, 2025 report linked a phishing campaign tracked from January to tactics associated with earlier WINELOADER activity attributed to APT29. Microsoft Threat Intelligence’s July 31, 2025 report described Secret Blizzard targeting foreign embassies in Moscow, with activity ongoing since at least 2024.
| Detail | APT29 campaign | Secret Blizzard campaign |
|---|---|---|
| Reporting source and date | Check Point Research, April 15, 2025 | Microsoft Threat Intelligence, July 31, 2025 |
| Actor attribution | APT29; Check Point associates the group with the Midnight Blizzard and Cozy Bear aliases | Secret Blizzard; Microsoft says CISA attributes the actor to Russia’s FSB, Center 16 |
| Reported malware | GRAPELOADER; a new WINELOADER variant was assessed as a likely later-stage payload | ApolloShadow |
| Reported access method | Phishing email, malicious archive and DLL side-loading | ISP- or telecommunications-level adversary-in-the-middle interception, captive-portal redirection and a disguised installer |
| Reported geography | European governments and diplomatic entities, including embassies of non-European countries in Europe; limited indications of targeting outside Europe | Foreign embassies in Moscow |
These are campaign targets, not proof that every recipient was compromised. The reports do not identify confirmed embassy victims or establish a total victim count.
How the APT29 GRAPELOADER campaign worked
Diplomatic invitations delivered the lure
Check Point described targeted emails impersonating a European Ministry of Foreign Affairs. The invitations, often framed around diplomatic events or wine tastings, encouraged recipients to follow a link. Subjects in identified messages included “Wine Event,” “Wine Testing Event,” “For Ambassador’s Calendar” and “Diplomatic dinner.” The emails were sent from at least two domains, `bakenhof[.]com` and `silry[.]com`. In some observed cases, a link redirected to the impersonated ministry’s official website instead of delivering the archive.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
GRAPELOADER established a foothold
In cases where the lure delivered its payload, a file named wine.zip contained a legitimate PowerPoint executable, a DLL dependency and an obfuscated DLL loader Check Point named GRAPELOADER. The loader used DLL side-loading: a legitimate executable was used to load a malicious DLL. GRAPELOADER established persistence through the Windows Run key, collected basic information about the host and waited for a later payload. Check Point characterized it as an initial-stage tool for fingerprinting, persistence and payload delivery.
WINELOADER was a likely later step, not a confirmed outcome for every target
Check Point found a new WINELOADER variant and assessed that it was likely delivered at a later stage. That wording matters: the report does not establish that every GRAPELOADER infection received WINELOADER, nor does it make the two names interchangeable. GRAPELOADER is the reported loader in the initial stage; WINELOADER is the likely subsequent payload in the researchers’ assessment.
How the separate ApolloShadow campaign targeted Moscow embassies
Interception led to a deceptive download prompt
Microsoft reported that Secret Blizzard used an adversary-in-the-middle position at the ISP or telecommunications level inside Russia. Target devices were redirected through a captive-portal flow to an actor-controlled domain. A certificate warning then prompted the user to download ApolloShadow, which masqueraded as a Kaspersky installer.
ApolloShadow changed device trust and access
Microsoft said ApolloShadow could install trusted root certificates, change network settings and create a local administrator account. A malicious root certificate can cause a device to trust actor-controlled sites; Microsoft said the capability could help Secret Blizzard maintain persistence and was likely intended for intelligence collection. Microsoft also assessed that interception could expose much of a target’s browsing in clear text, including some tokens and credentials.
Rank #3
This is not the reported delivery chain for GRAPELOADER. The Moscow campaign depended on network-level redirection and a deceptive installer, rather than the diplomatic-event phishing archive described by Check Point.
What diplomatic organizations can take from the reporting
Reduce exposure to untrusted network interception
For the ApolloShadow scenario, Microsoft recommended forcing or routing traffic through an encrypted tunnel to a trusted network, or using an alternative provider hosted in a country that does not control or influence its infrastructure. These are organizational routing and provider choices, not a recommendation for a particular consumer router or other retail device.
Rank #4
Investigate the behaviors, not just the malware names
For the APT29 activity, the reported behaviors to consider include unexpected diplomatic-event emails and archives, DLL side-loading, and persistence through the Windows Run key. For ApolloShadow, Microsoft’s account points to unexpected captive-portal prompts, certificate warnings, certificate-store changes, network-setting changes and new local administrator accounts. Microsoft also provided Microsoft Defender detection and response information; those detections should be treated as investigation aids, not a guarantee that a product blocks every attack.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why embassy targeting matters—and what it does not prove
ENISA’s 2025 Threat Landscape describes state-linked activity targeting diplomatic missions and other entities outside EU territory during Q3 2024 through Q2 2025. It notes APT29 activity against EU diplomatic missions abroad and explains that missions’ regular contact with Brussels and EU member-state capitals can make a compromised outpost a potential route toward core EU networks. That is a strategic risk, not evidence that onward movement occurred in either campaign discussed here.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
A separate Ukrainian government report describes an earlier APT29 operation in September 2023 targeting embassy and diplomatic accounts in Azerbaijan, Greece, Romania and Italy. It involved the WinRAR vulnerability CVE-2023-38831 and BMW car-sale lures. That incident is historical context, not evidence about GRAPELOADER or ApolloShadow.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

