Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SPIKEDWINE

Also known as: Midnight Blizzard, Cozy Bear, EnvyScout, VaporRage

Description

SPIKEDWINE is a threat actor targeting European officials with a new backdoor called WINELOADER. They use a bait PDF document posing as an invitation letter from the Ambassador of India to lure diplomats. The attack is characterized by advanced tactics, techniques, and procedures in the malware and command and control infrastructure. The motivation behind the attacks seems to be exploiting the geopolitical relations between India and European nations.

Goals & Targeting

Targeted Sectors

Government
Manufacturing
Think tank
Defense
Financial services

Targeted Countries / Regions

RU
UA
US
IN
TR
ES

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 6 MD5 Hash 13 URL 1

References

  1. research.checkpoint.com — Cited by web research for: Midnight Blizzard
  2. cloud.google.com — Cited by web research for: EnvyScout
  3. www.zscaler.com — Cited by web research for: T1053.005
  4. research.splunk.com — Cited by web research for: MuddyWater
  5. research.splunk.com — Cited by web research for: SQLDumper.exe

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Government Targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.