WINELOADER

Malware type
loader
Family
Malware family
Profile updated
2026-07-07 13:12:59

Context

WINELOADER is a malware loader used to deliver various types of malicious payloads. It facilitates the execution and installation of additional malware on compromised systems, often serving as the first stage in multi-step infection chains.

Detection coverage

  • 3 YARA rules

Detection rules

  • SEKOIA_Apt_Apt29_Wineloader_Malicious_Hta (yara-rule)
  • SEKOIA_Apt_Spikedwine_Wineloader (yara-rule)
  • SEKOIA_Apt_Apt29_Wineloader_Malicious_Pdf (yara-rule)

Reports & references

  • zscaler.com — European Diplomats Targeted Spikedwine Wineloader (report)
  • research.checkpoint.com — Apt29 Phishing Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Wineloader (report)
  • cert.ssi.gouv.fr — Certfr 2024 Cti 006 (report)
  • twitter.com — 1762549311294804145 (report)
  • Mandiant — Apt29 Wineloader German Political Parties (report)
  • twitter.com — 1763808104221737156 (report)
  • binarydefense.com — Wineloader Analysis Of The Infection Chain (report)

External references