ATT&CKReferencesCERT-UA WinterVivern 2023

CERT-UA WinterVivern 2023

CERT-UA. (2023, February 1). UAC-0114 aka Winter Vivern to target Ukrainian and Polish GOV entities (CERT-UA#5909). Retrieved July 29, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1041
Exfiltration Over C2 Channel
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1059.001
PowerShell
GroupWinter Vivern

Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations.

T1059.003
Windows Command Shell
GroupWinter Vivern

Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools.

T1071.001
Web Protocols
GroupWinter Vivern

Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.

T1113
Screen Capture
GroupWinter Vivern

Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines.

T1119
Automated Collection
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1189
Drive-by Compromise
GroupWinter Vivern

Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software.

T1204.001
Malicious Link
GroupWinter Vivern

Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution.

T1566.001
Spearphishing Attachment
GroupWinter Vivern

Winter Vivern leverages malicious attachments delivered via email for initial access activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.