GRAPELOADER
- First seen
- 2023-01-15 00:00:00
- Malware type
- loader
- Profile updated
- 2026-07-07 15:04:14
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
According to Checkpoint Research, GRAPELOADER is a newly observed initial-stage tool used for fingerprinting, persistence, and payload delivery. Despite differing roles, it shares similarities in code structure, obfuscation, and string decryption with WINELOADER. GRAPELOADER refines WINELOADER’s anti-analysis techniques while introducing more advanced stealth methods.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Grapeloader_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Grapeloader (report)
- research.checkpoint.com — Apt29 Phishing Campaign (report)