Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Russia-linked APT29 uses new malware in embassy attacks” combines two separate campaigns. Check Point Research reported APT29’s GRAPELOADER and WINELOADER activity against European diplomatic targets. Microsoft separately reported that Secret Blizzard used ApolloShadow in a campaign targeting foreign embassies in Moscow. The actors, malware and reported access methods are different.

What the reports actually describe

The two reports concern diplomatic targeting, but they do not describe one operation or a shared malware chain. Check Point Research’s April 15, 2025 report linked a phishing campaign tracked from January to tactics associated with earlier WINELOADER activity attributed to APT29. Microsoft Threat Intelligence’s July 31, 2025 report described Secret Blizzard targeting foreign embassies in Moscow, with activity ongoing since at least 2024.

Detail APT29 campaign Secret Blizzard campaign
Reporting source and date Check Point Research, April 15, 2025 Microsoft Threat Intelligence, July 31, 2025
Actor attribution APT29; Check Point associates the group with the Midnight Blizzard and Cozy Bear aliases Secret Blizzard; Microsoft says CISA attributes the actor to Russia’s FSB, Center 16
Reported malware GRAPELOADER; a new WINELOADER variant was assessed as a likely later-stage payload ApolloShadow
Reported access method Phishing email, malicious archive and DLL side-loading ISP- or telecommunications-level adversary-in-the-middle interception, captive-portal redirection and a disguised installer
Reported geography European governments and diplomatic entities, including embassies of non-European countries in Europe; limited indications of targeting outside Europe Foreign embassies in Moscow

These are campaign targets, not proof that every recipient was compromised. The reports do not identify confirmed embassy victims or establish a total victim count.

How the APT29 GRAPELOADER campaign worked

Diplomatic invitations delivered the lure

Check Point described targeted emails impersonating a European Ministry of Foreign Affairs. The invitations, often framed around diplomatic events or wine tastings, encouraged recipients to follow a link. Subjects in identified messages included “Wine Event,” “Wine Testing Event,” “For Ambassador’s Calendar” and “Diplomatic dinner.” The emails were sent from at least two domains, `bakenhof[.]com` and `silry[.]com`. In some observed cases, a link redirected to the impersonated ministry’s official website instead of delivering the archive.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GRAPELOADER established a foothold

In cases where the lure delivered its payload, a file named wine.zip contained a legitimate PowerPoint executable, a DLL dependency and an obfuscated DLL loader Check Point named GRAPELOADER. The loader used DLL side-loading: a legitimate executable was used to load a malicious DLL. GRAPELOADER established persistence through the Windows Run key, collected basic information about the host and waited for a later payload. Check Point characterized it as an initial-stage tool for fingerprinting, persistence and payload delivery.

WINELOADER was a likely later step, not a confirmed outcome for every target

Check Point found a new WINELOADER variant and assessed that it was likely delivered at a later stage. That wording matters: the report does not establish that every GRAPELOADER infection received WINELOADER, nor does it make the two names interchangeable. GRAPELOADER is the reported loader in the initial stage; WINELOADER is the likely subsequent payload in the researchers’ assessment.

How the separate ApolloShadow campaign targeted Moscow embassies

Interception led to a deceptive download prompt

Microsoft reported that Secret Blizzard used an adversary-in-the-middle position at the ISP or telecommunications level inside Russia. Target devices were redirected through a captive-portal flow to an actor-controlled domain. A certificate warning then prompted the user to download ApolloShadow, which masqueraded as a Kaspersky installer.

ApolloShadow changed device trust and access

Microsoft said ApolloShadow could install trusted root certificates, change network settings and create a local administrator account. A malicious root certificate can cause a device to trust actor-controlled sites; Microsoft said the capability could help Secret Blizzard maintain persistence and was likely intended for intelligence collection. Microsoft also assessed that interception could expose much of a target’s browsing in clear text, including some tokens and credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is not the reported delivery chain for GRAPELOADER. The Moscow campaign depended on network-level redirection and a deceptive installer, rather than the diplomatic-event phishing archive described by Check Point.

What diplomatic organizations can take from the reporting

Reduce exposure to untrusted network interception

For the ApolloShadow scenario, Microsoft recommended forcing or routing traffic through an encrypted tunnel to a trusted network, or using an alternative provider hosted in a country that does not control or influence its infrastructure. These are organizational routing and provider choices, not a recommendation for a particular consumer router or other retail device.

Investigate the behaviors, not just the malware names

For the APT29 activity, the reported behaviors to consider include unexpected diplomatic-event emails and archives, DLL side-loading, and persistence through the Windows Run key. For ApolloShadow, Microsoft’s account points to unexpected captive-portal prompts, certificate warnings, certificate-store changes, network-setting changes and new local administrator accounts. Microsoft also provided Microsoft Defender detection and response information; those detections should be treated as investigation aids, not a guarantee that a product blocks every attack.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why embassy targeting matters—and what it does not prove

ENISA’s 2025 Threat Landscape describes state-linked activity targeting diplomatic missions and other entities outside EU territory during Q3 2024 through Q2 2025. It notes APT29 activity against EU diplomatic missions abroad and explains that missions’ regular contact with Brussels and EU member-state capitals can make a compromised outpost a potential route toward core EU networks. That is a strategic risk, not evidence that onward movement occurred in either campaign discussed here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A separate Ukrainian government report describes an earlier APT29 operation in September 2023 targeting embassy and diplomatic accounts in Azerbaijan, Greece, Romania and Italy. It involved the WinRAR vulnerability CVE-2023-38831 and BMW car-sale lures. That incident is historical context, not evidence about GRAPELOADER or ApolloShadow.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.