Overview 38 indicators
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.
| url_path | 17 | G1035.json |
| domain | 16 | G1035-domain.txt |
| url | 5 | G1035.json |
Techniques 27 ATT&CK
Open in ATT&CK Navigator → or download the layer (27 techniques, layer 4.5)
- T1020 Automated Exfiltration
- T1033 System Owner/User Discovery
- T1036 Masquerading
- T1036.004 Masquerade Task or Service
- T1041 Exfiltration Over C2 Channel
- T1053.005 Scheduled Task
- T1056.003 Web Portal Capture
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.007 JavaScript
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1113 Screen Capture
- T1114.001 Local Email Collection
- T1119 Automated Collection
- T1140 Deobfuscate/Decode Files or Information
- T1189 Drive-by Compromise
- T1190 Exploit Public-Facing Application
- T1204.001 Malicious Link
- T1566.001 Spearphishing Attachment
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1584.006 Web Services
- T1595.002 Vulnerability Scanning
Principal sources 22 reports
Ranked by how many of this actor's indicators each report brought in.
- 14twitter.com/Cyber0verload/status/1620484493818855426
- 14cert.gov.ua/article/3761104
- 14virustotal.com/gui/ip-address/45.136.198.141/relations
- 14virustotal.com/gui/file/05457a790782542d3f16c9b8368a07…
- 14virustotal.com/gui/file/72028cff34d33e26bf01e4bf63c8b9…
- 5welivesecurity.com/en/eset-research/winter-vivern-exploits…
- 5otx.alienvault.com/pulse/653a74e3546b288fb2e329a3
- 5securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharp…
Timeline 38 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
welivesecurity.com/en/eset-research/winter-vivern-exploits… · otx.alienvault.com/pulse/653a74e3546b288fb2e329a3
recsecas.com -
proofpoint.com/us/blog/threat-insight/exploitation-dis…
nepalihemp.com oscp-avanguard.com -
twitter.com/felixaime/status/1636760060931248130 · twitter.com/Cyber0verload/status/1636773766679109632
ocsp-reloads.com ocsp-report.com -
bleepingcomputer.com/news/security/winter-vivern-apt-hackers… · sentinelone.com/labs/winter-vivern-uncovering-a-wave-of… · otx.alienvault.com/pulse/64134d77740d6bc14f3a8349 · virustotal.com/gui/file/a5115118908268569db2b1187b5b13…
domain marakanas.com domain ocs-romastassec.com url_path /Kkdn7862Jj6h2oDASGmpqU4Qq4q4.php url_path /goog_comredira3cf7ed34f8.php -
twitter.com/felixaime/status/1621189712105951232
applicationdevsoc.com security-ocsp.com -
twitter.com/Cyber0verload/status/1620484493818855426 · cert.gov.ua/article/3761104 · virustotal.com/gui/ip-address/45.136.198.141/relations · virustotal.com/gui/file/05457a790782542d3f16c9b8368a07… · virustotal.com/gui/file/72028cff34d33e26bf01e4bf63c8b9…
domain bugiplaysec.com domain ocspdep.com url_path /76bja21412/c6bd801d882333fdb93dd17308b3e2de3a78cc05_.php url_path /76bja21412/c6bd801d882333fdb93dd17308b3e2de3a78cc05_1.php url_path /c6bd801d882333fdb93dd17308b3e2de3a78cc05.php url_path /c6bd801d882333fdb93dd17308b3e2de3a78cc05_.php url_path /c6bd801d882333fdb93dd17308b3e2de3a78cc05_1.php url_path /fjasmngptwq214.php url_path /fjasmngptwq95824s.php url_path /fx64g15g.xml url_path /gkaslnwqpasg/fx64g15g.xml url_path /gkaslnwqpasg/usersfolders/ url_path /lg5362s5215098-xvbxzcnsaf4lmsa.php -
twitter.com/Cyber0verload/status/1620484493818855426 · cert.gov.ua/article/3761104 · virustotal.com/gui/ip-address/45.136.198.141/relations · virustotal.com/gui/file/05457a790782542d3f16c9b8368a07… · virustotal.com/gui/file/72028cff34d33e26bf01e4bf63c8b9…
troadsecow.com -
welivesecurity.com/en/eset-research/winter-vivern-exploits… · otx.alienvault.com/pulse/653a74e3546b288fb2e329a3
/wintervivern/server/ /wintervivern/vivern/ /wintervivern/vivern/getAnswer.php?username= /wintervivern/vivern/getcommand?username= -
domaintools.com/resources/blog/winter-vivern-a-look-at-… · lab52.io/blog/winter-vivern-all-summer · otx.alienvault.com/pulse/6152feb7f8ed6979d6eb5c10
centr-security.com secure-daddy.com securemanage.com securetourspd.com -
securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharp… · mcafee.com/enterprise/en-us/assets/reports/rp-oper… · github.com/advanced-threat-research/IOCs/blob/mast… · virustotal.com/gui/file/88a5287b6e9879e79240660408e2e8…
http://137.74.41.56 http://34.214.99.20 -
securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharp… · mcafee.com/enterprise/en-us/assets/reports/rp-oper… · github.com/advanced-threat-research/IOCs/blob/mast… · virustotal.com/gui/file/88a5287b6e9879e79240660408e2e8…
http://208.117.44.112 -
securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharp… · mcafee.com/enterprise/en-us/assets/reports/rp-oper… · github.com/advanced-threat-research/IOCs/blob/mast… · virustotal.com/gui/file/88a5287b6e9879e79240660408e2e8…
kingkoil.com.sg/query.php -
securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharp… · mcafee.com/enterprise/en-us/assets/reports/rp-oper… · github.com/advanced-threat-research/IOCs/blob/mast… · virustotal.com/gui/file/88a5287b6e9879e79240660408e2e8…
kingkoil.com.sg/board.php
Further reading 24
- attack.mitre.org/groups/G1035
- cert.gov.ua/article/3761104
- domaintools.com/resources/blog/winter-vivern-a-look-at-…
- proofpoint.com/us/blog/threat-insight/exploitation-dis…
- sentinelone.com/labs/winter-vivern-uncovering-a-wave-of…
- welivesecurity.com/en/eset-research/winter-vivern-exploits…
- otx.alienvault.com/pulse/6152feb7f8ed6979d6eb5c10
- github.com/advanced-threat-research/IOCs/blob/mast…
- securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharp…
- otx.alienvault.com/pulse/653a74e3546b288fb2e329a3
- virustotal.com/gui/file/05457a790782542d3f16c9b8368a07…
- domaintools.com/resources/blog/winter-vivern-a-look-at-…
- twitter.com/Cyber0verload/status/1620484493818855426
- twitter.com/felixaime/status/1636760060931248130
- otx.alienvault.com/pulse/64134d77740d6bc14f3a8349
- twitter.com/felixaime/status/1621189712105951232
- lab52.io/blog/winter-vivern-all-summer
- virustotal.com/gui/file/72028cff34d33e26bf01e4bf63c8b9…
- mcafee.com/enterprise/en-us/assets/reports/rp-oper…
- virustotal.com/gui/file/88a5287b6e9879e79240660408e2e8…
- bleepingcomputer.com/news/security/winter-vivern-apt-hackers…
- virustotal.com/gui/ip-address/45.136.198.141/relations
- virustotal.com/gui/file/a5115118908268569db2b1187b5b13…
- twitter.com/Cyber0verload/status/1636773766679109632