Threat group.View on attack.mitre.org
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.
| Technique | Procedure example |
|---|---|
| T1020 Automated Exfiltration |
Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1033 System Owner/User Discovery |
Winter Vivern PowerShell scripts execute `whoami` to identify the executing user. |
| T1036 Masquerading |
Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns. |
| T1036.004 Masquerade Task or Service |
Winter Vivern has distributed malicious scripts and executables mimicking virus scanners. |
| T1041 Exfiltration Over C2 Channel |
Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1053.005 Scheduled Task |
Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads. |
| T1056.003 Web Portal Capture |
Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information. |
| T1059 Command and Scripting Interpreter |
Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files. |
| T1059.001 PowerShell |
Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations. |
| T1059.003 Windows Command Shell |
Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools. |
| T1059.007 JavaScript |
Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers. |
| T1071.001 Web Protocols |
Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity. |
| T1082 System Information Discovery |
Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers. |
| T1083 File and Directory Discovery |
Winter Vivern delivered malicious JavaScript payloads capable of listing folders and emails in exploited email servers. |
| T1105 Ingress Tool Transfer |
Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.