Winter Vivern — APT Profile
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.Also tracked as
TA473, UAC-0114
Vendor research
- UAC-0114 aka Winter Vivern to target Ukrainian and Polish GOV entities (CERT-UA#5909) CERT-UA
- Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages DomainTools
- Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers ESET
- Exploitation is a Dish Best Served Cold: Winter Vivern Uses Known Zimbra Vulnerability to Target Webmail Portals of NATO-Aligned Governments in Europe Proofpoint
- Winter Vivern | Uncovering a Wave of Global Espionage SentinelOne