Winter Vivern is a cyberespionage group primarily targeting European governments.
Analyst brief
Winter Vivern is a cyberespionage group active since at least 2020. It targets governments, primarily in Germany, Europe, and Central Asia. Key TTPs include Spearphishing Attachments, Drive-by Compromise, and a custom PowerShell backdoor. Defenders should focus on detecting obfuscated JavaScript payloads, C2 traffic via Web Protocols from VPS/Web Services, and credential theft attempts through Web Portal Capture.
Winter Vivern
UAC-0114TA473TAG-70
unknown
Winter Vivern is a cyberespionage group first revealed by DomainTools in 2021. It is thought to have been active since at least 2020 and it targets governments in Europe and Central Asia. To compromise its targets, the group uses malicious documents, phishing websites, and a custom PowerShell backdoor.