Winter Vivern is a Russia-aligned cyber-espionage threat actor tracked under aliases including TA473 and UAC-0114. The group is known for targeting government, diplomatic, military, and other high-value organizations, particularly across Europe and Asia, with a strong emphasis on webmail-centric intrusion activity. Winter Vivern has repeatedly focused on stealing emails, credentials, and related account data from internet-facing mail platforms, especially Zimbra and Roundcube deployments. The actor is associated with phishing for credentials and exploitation of public-facing webmail applications. Reported activity includes exploitation of Zimbra vulnerabilities such as CVE-2022-27926 and reflected or stored cross-site scripting flaws to compromise webmail portals and steal mailbox contents from NATO-aligned organizations, government officials, military personnel, and diplomats. Winter Vivern has also been linked to targeting Roundcube in campaigns aimed at high-value email communications. In some operations, the group delivered malicious JavaScript payloads that interacted directly with compromised mail interfaces to enumerate folders and emails and facilitate theft of message data. Observed tradecraft and ATT&CK mappings associated with Winter Vivern include exploitation of public-facing applications, credential phishing, PowerShell and other command-and-scripting interpreter use, DNS-based command and control, masquerading, automated collection, and post-compromise discovery. The group has been associated with credential theft and email collection objectives rather than disruptive or financially motivated operations. Winter Vivern is widely characterized as a state-sponsored espionage actor aligned with Russian interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
Typical compromise chain ... https://<victim’s Zimbra domain>/public/error.jsp?errCode= ... CVE-2022-27926 ... Government staff Europe and Asia ... Phishing for credentials Zimbra Winter Vivern
ESET Research ... found that the group began exploiting a zero-day XSS vulnerability in the Roundcube Webmail server ... assigned CVE-2023-5631 ... affecting the server-side script rcube_washtml.php ... patched on October 14th, 2023 ... security updates ... (1.6.4, 1.5.5, and 1.4.15).
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
... different vulnerability than CVE-2020-35730 ... the group exploited CVE-2020-35730, another XSS vulnerability in Roundcube, in August and September 2023. Note that Sednit (also known as APT28) is exploiting this old XSS vulnerability in Roundcube as well ...
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Acteurs de menace # TA488 (state-sponsored) ... TA473 (state-sponsored) ...
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.