WINELOADER
- Malware type
- loader
- Family
- Malware family
- Profile updated
- 2026-07-07 13:12:59
Context
WINELOADER is a malware loader used to deliver various types of malicious payloads. It facilitates the execution and installation of additional malware on compromised systems, often serving as the first stage in multi-step infection chains.
Detection coverage
- 3 YARA rules
Detection rules
- SEKOIA_Apt_Apt29_Wineloader_Malicious_Hta (yara-rule)
- SEKOIA_Apt_Spikedwine_Wineloader (yara-rule)
- SEKOIA_Apt_Apt29_Wineloader_Malicious_Pdf (yara-rule)
Reports & references
- zscaler.com — European Diplomats Targeted Spikedwine Wineloader (report)
- research.checkpoint.com — Apt29 Phishing Campaign (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Wineloader (report)
- cert.ssi.gouv.fr — Certfr 2024 Cti 006 (report)
- twitter.com — 1762549311294804145 (report)
- Mandiant — Apt29 Wineloader German Political Parties (report)
- twitter.com — 1763808104221737156 (report)
- binarydefense.com — Wineloader Analysis Of The Infection Chain (report)