Also known as: TA473, UAC-0114, TAG-70, TA-473
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.(Citation: DomainTools WinterVivern 2021)(Citation: SentinelOne WinterVivern 2023)(Citation: CERT-UA WinterVivern 2023)(Citation: ESET WinterVivern 2023)(Citation: Proofpoint WinterVivern 2023)
Executive Summary
Winter Vivern is a cyber threat actor group linked to Russian and Belorussian interests, active since at least 2020. The group primarily targets European government entities, NGOs, and occasionally Indian and U.S. victims. Their tactics include document-based phishing and server-side exploitation for initial access, followed by the use of adversary-controlled infrastructure for command and control. Winter Vivern appears to have a high level of technical sophistication, with a focus on persistent and targeted operations likely aimed at espionage or data collection.
Goals & Targeting
Winter Vivern's strategic objectives appear to align with those of state-sponsored actors, given their ties to Russian and Belorussian interests. Their targeting of European governments and NGOs suggests an interest in geopolitical influence, espionage, or critical infrastructure. The occasional targeting of Indian and U.S. entities may indicate either opportunistic activity or a broader effort to disrupt strategic adversaries. Winter Vivern's victims are likely selected based on their potential to yield sensitive information or disrupt operations, aligning with the group's technical capabilities for long-term persistence.
Enhanced Description
Winter Vivern is an active cyber threat group identified as TA473, UAC-0114, TAG-70, or TA-473. The group has been observed since at least 2020 and is linked to Russian and Belorussian geopolitical interests. Their primary targets include European government entities, NGOs, and sporadic activity against Indian and U.S. victims. Winter Vivern employs a combination of document-based phishing campaigns and server-side exploitation techniques for initial access. After compromising systems, the group uses adversary-controlled infrastructure to establish command and control (C2) communication. This suggests a high level of operational maturity and resource allocation towards maintaining persistent access. The group's use of custom tools and infrastructure indicates that they are likely targeting specific high-value assets for intelligence gathering or other strategic purposes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Winter Vivern has demonstrated consistent activity since its first identification in 2020. Their campaigns typically involve targeted phishing attempts, often using spear-phishing attachments to gain initial access. Once inside a network, the group establishes persistence and begins lateral movement to achieve their goals. The use of server-side exploitation indicates a focus on high-value targets that may require more advanced techniques to compromise. Winter Vivern's operations appear to be well-coordinated, with an emphasis on maintaining long-term access through custom infrastructure. Notable past operations include attacks against European government entities and NGOs, suggesting a focus on intelligence gathering from these sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a high level of confidence in Winter Vivern's activity due to multiple reliable intelligence sources, including DomainTools, SentinelOne, CERT-UA, and ESET. The group's use of sophisticated techniques and clear targeting patterns supports their classification as an advanced persistent threat (APT) group linked to Russian and Belorussian interests. However, gaps remain in understanding the group's specific tools and exact motivations beyond high-level observations.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
27
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
9
Tactics