2 min read

APT29 Deploys New DiploCrypt Malware in Espionage Campaign Against European Diplomats

Russian-linked advanced persistent threat group Cozy Bear has launched a new espionage campaign targeting diplomatic institutions and foreign affairs ministries across Europe and Southeast Asia. Cybersecurity firm Mandiant, which tracks the group as APT29, published a detailed analysis of the campaign revealing previously unseen malware and novel command-and-control techniques.

A New Toolset Emerges

The campaign, active since at least March 2026, employs a new malware family that Mandiant has designated “DiploCrypt.” Unlike previous APT29 tools that relied on commodity frameworks, DiploCrypt is a custom-built implant written in Rust, a programming language increasingly favored by sophisticated threat actors for its performance and memory safety features.

DiploCrypt uses encrypted DNS-over-HTTPS (DoH) queries for command-and-control communications, making its traffic nearly indistinguishable from legitimate web browsing. The malware can exfiltrate documents, capture screenshots, record keystrokes, and maintain persistent access across system reboots through a novel Windows Task Scheduler abuse technique.

Initial Access Vector

The attackers gain initial access through meticulously crafted spear-phishing emails that impersonate legitimate diplomatic communications. In one documented case, the phishing lure was a convincing replica of an official invitation to a G20 preparatory meeting, complete with accurate formatting and the correct email signatures of real diplomats.

“The level of social engineering sophistication we are seeing from APT29 continues to escalate,” said John Hultquist, Mandiant’s chief analyst. “These are not generic phishing attempts. Each lure is tailored to the specific target and their professional context.”

Targets and Objectives

Mandiant identified confirmed compromises at foreign affairs ministries in three European countries and two Southeast Asian nations. The attackers appeared primarily interested in documents related to sanctions policy, defense cooperation agreements, and diplomatic cables discussing relations with Russia.

The campaign also targeted several think tanks and policy research organizations that advise governments on foreign policy, suggesting a broad intelligence collection mandate.

Attribution and Context

Mandiant attributed the campaign to APT29 with high confidence based on overlapping infrastructure, code similarities with previously documented APT29 tools, and targeting patterns consistent with Russian intelligence priorities. The group, also known as Cozy Bear and The Dukes, has been linked to Russia’s Foreign Intelligence Service (SVR).

Defensive Guidance

Mandiant has published indicators of compromise and detection rules for DiploCrypt in its public threat intelligence portal. The firm recommends that diplomatic institutions implement advanced email filtering, monitor for anomalous DNS-over-HTTPS traffic, and conduct regular threat hunting exercises focused on the MITRE ATT&CK techniques associated with APT29.

Government cybersecurity agencies in affected countries have been notified and are coordinating response efforts through established intelligence sharing channels.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.