ATT&CKGroupsWinter Vivern

Winter Vivern

G1035

Threat group.View on attack.mitre.org

About this group

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.

Techniques used27

Procedure examples27

TechniqueProcedure example
T1020
Automated Exfiltration

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1033
System Owner/User Discovery

Winter Vivern PowerShell scripts execute `whoami` to identify the executing user.

T1036
Masquerading

Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns.

T1036.004
Masquerade Task or Service

Winter Vivern has distributed malicious scripts and executables mimicking virus scanners.

T1041
Exfiltration Over C2 Channel

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1053.005
Scheduled Task

Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads.

T1056.003
Web Portal Capture

Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information.

T1059
Command and Scripting Interpreter

Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files.

T1059.001
PowerShell

Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations.

T1059.003
Windows Command Shell

Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools.

T1059.007
JavaScript

Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers.

T1071.001
Web Protocols

Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.

T1082
System Information Discovery

Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers.

T1083
File and Directory Discovery

Winter Vivern delivered malicious JavaScript payloads capable of listing folders and emails in exploited email servers.

T1105
Ingress Tool Transfer

Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.

View all 27 procedure examples

Software0

None recorded.

Campaigns0

None recorded.

References5

  1. CERT-UA WinterVivern 2023 Open source
    CERT-UA. (2023, February 1). UAC-0114 aka Winter Vivern to target Ukrainian and Polish GOV entities (CERT-UA#5909). Retrieved July 29, 2024.
  2. DomainTools WinterVivern 2021 Open source
    Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.
  3. ESET WinterVivern 2023 Open source
    Matthieu Faou. (2023, October 25). Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers. Retrieved July 29, 2024.
  4. Proofpoint WinterVivern 2023 Open source
    Michael Raggi & The Proofpoint Threat Research Team. (2023, March 30). Exploitation is a Dish Best Served Cold: Winter Vivern Uses Known Zimbra Vulnerability to Target Webmail Portals of NATO-Aligned Governments in Europe. Retrieved July 29, 2024.
  5. SentinelOne WinterVivern 2023 Open source
    Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.