Russian Federation-backed threat group APT29 Now Targeting German Political Parties

Stu Sjouwerman | Mar 29, 2024

Russian Federation-based Threat Group

New analysis of APT29’s (aka Cozy Bear) activities and their association with Russia’s Foreign Intelligence Service (SVR) has revealed suspected attempts to collect political intelligence.

 

Last month, security researchers at Mandiant identified an attack targeting German political parties using a new backdoor malware dubbed WINELOADER.

In a just-released analysis of the attacks, Mandian analysts noted some changes in the execution methods of APT29 that go back to 2021.

First is the use of German-language content — a possible sign of the use of generative AI to create content native to the targeted victims. Under the guise of an invitation a dinner reception while impersonating the Christian Democratic Union political party, the phishing email linked to a dropper hosted on a compromised  website.

The second change in execution is the target. Historically, APT29 has been responsible for attacks like the SolarWinds attack in 2020. According to Mandiant, the threat group was seen targeting political targets in Czechia, Germany, India, Italy, Latvia, and Peru — indicating a shift to likely aiding SVR with the collection of political intelligence.

The good news is their email is horrible — take a look.

apt29-wineloader-fig1

Source: Mandiant

So, only those that simply aren’t paying attention will fall for it.  But that’s just it most of your employees aren’t paying attention; they’re busy doing their real job. To get them to truly spot a potential phishing-based threat and avoid becoming a victim takes continual reinforcement through new-school security awareness training that establishes a sense of vigilance within the employee so being suspicious of such an email as the one above becomes second nature.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.