Winter Vivern
· Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
· Source: The MITRE Corporation
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 27/03/2026 01:14
- Updated at
- 27/03/2026 01:14
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 37 attack patterns (mitre), 6 malware, 5 sectors, 8 countries, 27 indicators, 3 vulnerabilities (cve)
Aliases
UAC-0114 TA473
Description
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.(Citation: DomainTools WinterVivern 2021)(Citation: SentinelOne WinterVivern 2023)(Citation: CERT-UA WinterVivern 2023)(Citation: ESET WinterVivern 2023)(Citation: Proofpoint WinterVivern 2023)
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (37)
-
T1119 usesAutomated Collection
-
T1189 usesDrive-by Compromise
-
T1059.007 usesJavaScript
-
T1056 usesInput Capture
-
T1190 usesExploit Public-Facing Application
-
T1036 usesMasquerading
-
T1056.003 usesWeb Portal Capture
-
T1082 usesSystem Information Discovery
-
T1204 usesUser Execution
-
T1027 usesObfuscated Files or Information
-
T1059 usesCommand and Scripting Interpreter
-
T1566 usesPhishing
-
T1071 usesApplication Layer Protocol
-
T1071.001 usesWeb Protocols
-
T1583.001 usesDomains
-
T1105 usesIngress Tool Transfer
-
T1595.002 usesVulnerability Scanning
-
T1573 usesEncrypted Channel
-
T1003 usesOS Credential Dumping
-
T1566.001 usesSpearphishing Attachment
-
T1068 usesExploitation for Privilege Escalation
-
T1059.003 usesWindows Command Shell
-
T1036.004 usesMasquerade Task or Service
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1053.005 usesScheduled Task
-
T1059.001 usesPowerShell
-
T1204.001 usesMalicious Link
-
T1113 usesScreen Capture
-
T1134 usesAccess Token Manipulation
-
T1020 usesAutomated Exfiltration
-
T1055 usesProcess Injection
-
T1083 usesFile and Directory Discovery
-
T1114.001 usesLocal Email Collection
-
T1584.006 usesWeb Services
-
T1041 usesExfiltration Over C2 Channel
-
T1583.003 usesVirtual Private Server
-
T1033 usesSystem Owner/User Discovery
Malware (6)
- Prev IceFire
- Winter Vivern
- MailCopter
- Zebrocy
- Zebrocy - S0251
- IceFire
Sectors (5)
- Diplomacy targets
- Telecommunications targets
- Defense ministries (including the military) targets
- Government targets
- Ministries of foreign affairs targets
Countries (8)
- Poland targets
- Estonia targets
- Ukraine targets
- India targets
- United States of America targets
- Lithuania targets
- Slovakia targets
- Italy targets
Indicators (27)
-
https://ocs-romastassec.com/redirect/?id=[targetindicates -
hitsbitsx.comindicates -
https://troadsecow.com/cbzc.policja.gov.plindicates -
marakanas.comindicates -
ocspdep.comindicates -
ocs-romastassec.comindicates -
https://oscp-avanguard.com/asn15180YHASIFHOP_indicates -
troadsecow.comindicates -
security-ocsp.comindicates -
ocsp-reloads.comindicates -
https://ocs-romastassec.com/goog_comredira3cf7ed34f8.phpindicates -
http://ocs-romastassec.com/goog_comredira3cf7ed34f8.phpindicates -
https://marakanas.com/Kkdn7862Jj6h2oDASGmpqU4Qq4q4.phpindicates -
https://nepalihemp.com/assets/img/images/623930vaindicates -
https://natply.com/wordpress/wp-includes/fonts/ch/097214oindicates -
bugiplaysec.comindicates -
6800357ec3092c56aab17720897c29bb389f70cb49223b289ea5365314199a26indicates -
https://bugiplaysec.com/mgu/auth.jsindicates -
https://applesaltbeauty.com/wordpress/wp-includes/widgets/classwp/521734iindicates -
https://ocs-romastassec.com/goog_comredira3cf7ed34f8.php'indicates -
oscp-avanguard.comindicates -
recsecas.comindicates -
https://oscp-avanguard.com/settingPopImap/SettingupPOPandIMAPaccounts.htmlindicates -
ea22b3e9ecdfd06fae74483deb9ef0245aefdc72f99120ae6525c0eaf37de32eindicates -
https://marakanas.com/Kkdn7862Jj6h2oDASGmpqU4Qq4q4.php?idU=$aindicates -
nepalihemp.comindicates -
https://ocspdep.com/inotes.sejm.gov.pl?id=[Targetindicates
Vulnerabilities (CVE) (3)
CVE-2022-27926
KEV
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.
- Published
- 03/04/2023
- Modified
- 20/12/2025
CVE-2022-30190
KEV
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An …
- Published
- 14/06/2022
- Modified
- 27/05/2026
6.1
Medium
An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability …
- Attack vector
- NETWORK
- Published
- 02/07/2021
- Modified
- 20/12/2025