G1035: Winter Vivern
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.[1][2][3][4][5]
Security context for executives and security teams
G1035: Winter Vivern describes Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.(Citation: DomainTools WinterVivern 2021)(Citation: SentinelOne WinterVivern 2023)(Citation: CERT-U...
Executive priority
G1035: Winter Vivern is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1035: Winter Vivern by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1035: Winter Vivern appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Winter Vivern
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.[1][2][3][4][5]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1059 | Command and Scripting Interpreter | Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files.[1] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.[2][3] |
| Enterprise | T1056.003 | Web Portal CaptureSub-technique | Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information.[2] |
| Enterprise | T1033 | System Owner/User Discovery | Winter Vivern PowerShell scripts execute `whoami` to identify the executing user.[2] |
| Enterprise | T1583.003 | Virtual Private ServerSub-technique | Winter Vivern used adversary-owned and -controlled servers to host web vulnerability scanning applications.[2] |
| Enterprise | T1059.007 | JavaScriptSub-technique | Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers.[4] |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | Winter Vivern leverages malicious attachments delivered via email for initial access activity.[1][2][3] |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | Winter Vivern has distributed malicious scripts and executables mimicking virus scanners.[2] |
| Enterprise | T1113 | Screen Capture | Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines.[3] |
| Enterprise | T1189 | Drive-by Compromise | Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software.[3] |
| Enterprise | T1119 | Automated Collection | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.[3] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Winter Vivern delivered exploit payloads via base64-encoded payloads in malicious email messages.[4] |
| Enterprise | T1020 | Automated Exfiltration | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.[3] |
| Enterprise | T1105 | Ingress Tool Transfer | Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.[1] |
| Enterprise | T1190 | Exploit Public-Facing Application | Winter Vivern has exploited known and zero-day vulnerabilities in software usch as Roundcube Webmail servers and the "Follina" vulnerability.[4][5] |
| Enterprise | T1595.002 | Vulnerability ScanningSub-technique | Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner.[2] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.[3] |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads.[1] |
| Enterprise | T1584.006 | Web ServicesSub-technique | Winter Vivern has used compromised WordPress sites to host malicious payloads for download.[2] |
| Enterprise | T1036 | Masquerading | Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns.[2] |
| Enterprise | T1583.001 | DomainsSub-technique | Winter Vivern registered domains mimicking other entities throughout various campaigns.[1] |
| Enterprise | T1082 | System Information Discovery | Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers.[1] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools.[2][3] |
| Enterprise | T1204.001 | Malicious LinkSub-technique | Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution.[2][3] |
| Enterprise | T1083 | File and Directory Discovery | Winter Vivern delivered malicious JavaScript payloads capable of listing folders and emails in exploited email servers.[4] |
| Enterprise | T1114.001 | Local Email CollectionSub-technique | Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers.[4] |
| Enterprise | T1059.001 | PowerShellSub-technique | Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations.[1] Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations.[3] |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | c52aad5861e3… | ||
| 19.1 | 1.0 | Older bundle | 8a04cd4c4751… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]DomainTools WinterVivern 2021
Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.
Open source URL - [2]SentinelOne WinterVivern 2023
Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.
Open source URL - [3]CERT-UA WinterVivern 2023
CERT-UA. (2023, February 1). UAC-0114 aka Winter Vivern to target Ukrainian and Polish GOV entities (CERT-UA#5909). Retrieved July 29, 2024.
Open source URL - [4]ESET WinterVivern 2023
Matthieu Faou. (2023, October 25). Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers. Retrieved July 29, 2024.
Open source URL - [5]Proofpoint WinterVivern 2023
Michael Raggi & The Proofpoint Threat Research Team. (2023, March 30). Exploitation is a Dish Best Served Cold: Winter Vivern Uses Known Zimbra Vulnerability to Target Webmail Portals of NATO-Aligned Governments in Europe. Retrieved July 29, 2024.
Open source URL - [6]TA473
(Citation: Proofpoint WinterVivern 2023)
- [7]UAC-0114
(Citation: CERT-UA WinterVivern 2023)
- [8]mitre-attackG1035Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
