Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Winter Vivern

Also known as: TA473, UAC-0114, TAG-70, TA-473

Description

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.(Citation: DomainTools WinterVivern 2021)(Citation: SentinelOne WinterVivern 2023)(Citation: CERT-UA WinterVivern 2023)(Citation: ESET WinterVivern 2023)(Citation: Proofpoint WinterVivern 2023)

AI Analysis

· 1 week ago

Executive Summary

Winter Vivern is a cyber threat actor group linked to Russian and Belorussian interests, active since at least 2020. The group primarily targets European government entities, NGOs, and occasionally Indian and U.S. victims. Their tactics include document-based phishing and server-side exploitation for initial access, followed by the use of adversary-controlled infrastructure for command and control. Winter Vivern appears to have a high level of technical sophistication, with a focus on persistent and targeted operations likely aimed at espionage or data collection.

Goals & Targeting

Winter Vivern's strategic objectives appear to align with those of state-sponsored actors, given their ties to Russian and Belorussian interests. Their targeting of European governments and NGOs suggests an interest in geopolitical influence, espionage, or critical infrastructure. The occasional targeting of Indian and U.S. entities may indicate either opportunistic activity or a broader effort to disrupt strategic adversaries. Winter Vivern's victims are likely selected based on their potential to yield sensitive information or disrupt operations, aligning with the group's technical capabilities for long-term persistence.

Enhanced Description

Winter Vivern is an active cyber threat group identified as TA473, UAC-0114, TAG-70, or TA-473. The group has been observed since at least 2020 and is linked to Russian and Belorussian geopolitical interests. Their primary targets include European government entities, NGOs, and sporadic activity against Indian and U.S. victims. Winter Vivern employs a combination of document-based phishing campaigns and server-side exploitation techniques for initial access. After compromising systems, the group uses adversary-controlled infrastructure to establish command and control (C2) communication. This suggests a high level of operational maturity and resource allocation towards maintaining persistent access. The group's use of custom tools and infrastructure indicates that they are likely targeting specific high-value assets for intelligence gathering or other strategic purposes.

Key Capabilities

  • Document-based phishing campaigns
  • Server-side exploitation for initial access
  • Adversary-controlled infrastructure for C2 communication
  • Sophisticated TTPs aligned with advanced persistent threat (APT) groups

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1053.005: Scheduled Task
T1113: Screen Capture
T1059.007: JavaScript
T1114.001: Local Email Collection
T1119: Automated Collection
T1036: Masquerading
T1190: Exploit Public-Facing Application
T1583.001: Domains
T1595.002: Vulnerability Scanning
T1036.004: Masquerade Task or Service
T1056.003: Web Portal Capture
T1020: Automated Exfiltration
T1583.003: Virtual Private Server
T1083: File and Directory Discovery
T1041: Exfiltration Over C2 Channel
T1059.001: PowerShell
T1059.003: Windows Command Shell
T1071.001: Web Protocols
T1204.001: Malicious Link
T1033: System Owner/User Discovery
T1566.001: Spearphishing Attachment
T1082: System Information Discovery
T1140: Deobfuscate/Decode Files or Information

Software / Tooling

Adversary-controlled tools for C2 communication
Custom malware likely used in their campaigns
Document-based exploit frameworks

Campaigns & Victims

Winter Vivern has demonstrated consistent activity since its first identification in 2020. Their campaigns typically involve targeted phishing attempts, often using spear-phishing attachments to gain initial access. Once inside a network, the group establishes persistence and begins lateral movement to achieve their goals. The use of server-side exploitation indicates a focus on high-value targets that may require more advanced techniques to compromise. Winter Vivern's operations appear to be well-coordinated, with an emphasis on maintaining long-term access through custom infrastructure. Notable past operations include attacks against European government entities and NGOs, suggesting a focus on intelligence gathering from these sectors.

IOC Patterns

  • Spear-phishing using document-based attachments
  • Use of server-side exploitation techniques for initial access
  • Establishment of C2 communication over adversary-controlled domains
  • Presence of scheduled tasks or persistence mechanisms in targeted systems

Recommended Actions

  • Implement strong phishing detection solutions to identify spear-phishing attempts.
  • Monitor for and block known malicious domains associated with Winter Vivern activity.
  • Conduct regular network traffic analysis to detect server-side exploitation attempts.
  • Enhance endpoint protection to prevent initial access via document-based exploits.
  • Use SIEM tools to detect unusual scheduled task activity and C2 communication patterns.

Suggested Tags

APT
espionage
cyber-espionage
European targets
government targeting
NGO targeting

Confidence Assessment

There is a high level of confidence in Winter Vivern's activity due to multiple reliable intelligence sources, including DomainTools, SentinelOne, CERT-UA, and ESET. The group's use of sophisticated techniques and clear targeting patterns supports their classification as an advanced persistent threat (APT) group linked to Russian and Belorussian interests. However, gaps remain in understanding the group's specific tools and exact motivations beyond high-level observations.

ATT&CK Techniques

Collection
4 techniques
Execution
6 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. CERT-UA WinterVivern 2023 — CERT-UA. (2023, February 1). UAC-0114 aka Winter Vivern to target Ukrainian and Polish GOV entities (CERT-UA#5909). Retrieved July 29, 2024.
  2. DomainTools WinterVivern 2021 — Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.
  3. ESET WinterVivern 2023 — Matthieu Faou. (2023, October 25). Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers. Retrieved July 29, 2024.
  4. Proofpoint WinterVivern 2023 — Michael Raggi & The Proofpoint Threat Research Team. (2023, March 30). Exploitation is a Dish Best Served Cold: Winter Vivern Uses Known Zimbra Vulnerability to Target Webmail Portals of NATO-Aligned Governments in Europe. Retrieved July 29, 2024.
  5. SentinelOne WinterVivern 2023 — Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.

Intel Summary

27

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

9

Tactics

Tags

Phishing
Backdoor / C2
Government Targeting
APT
espionage
cyber-espionage
European targets
government targeting
NGO targeting

Details

MITRE ID
G1035
Type
Unknown
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--75a07184-a7e5-4222-95a1-a04dbc96a29c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.