>samit_hota
Back to adversary profiles

Threat Actor Dossier

Winter Vivern: Relentless Espionage Targeting Europe

G1035

Also tracked as TA473 · UAC-0114 · 10 sectors targeted

Threat level
HIGH
Status
ACTIVE
Origin
Russia, Belarus
Motivation
Espionage · Intelligence Gathering
Samit Hota·
Target Sectors
Government, Military, Telecommunications, Aerospace & Defense, Chemicals, Law Enforcement Agencies, Transport, Education, Satellite Communication Providers, Think Tanks
Associated Malware
APERETIF, Winter Wyvern, custom PowerShell backdoor
#threat-actor#g1035

Overview

Winter Vivern (MITRE ATT&CK G1035), also tracked as TA473 and UAC-0114, is a persistent and resourceful cyber espionage group that has been active since at least 2020. This threat actor is closely aligned with Russian and Belarusian government interests, with its operations often coinciding with geopolitical objectives in Eastern Europe. While not always employing the most advanced or unique tooling, Winter Vivern consistently demonstrates creativity and flexibility, effectively leveraging publicly available resources and known vulnerabilities to achieve its objectives.

The primary motivation behind Winter Vivern’s activities is intelligence gathering, aiming for long-term persistence within targeted networks, credential theft, and potentially the disruption of military communications. The group’s targeting is broad but strategically focused, primarily impacting European governments, particularly ministries of foreign affairs and defense, diplomatic missions, and entities associated with NATO. Beyond these core government targets, Winter Vivern has also shown interest in critical infrastructure sectors, including telecommunications, aerospace and defense, chemicals, law enforcement agencies, transport, and education. Geographically, they have actively targeted Ukraine, Poland, Lithuania, India, the Vatican, Slovakia, Italy, Georgia, Moldova, Uzbekistan, and Tunisia, with sporadic targeting of organizations in the United States.

Tactics & Techniques

Winter Vivern employs a multi-faceted approach to gain initial access, predominantly relying on sophisticated phishing campaigns and the exploitation of public-facing applications, especially webmail servers. Their phishing operations are characterized by high-quality lures, often impersonating legitimate government agencies, NATO bodies, or health organizations. These lures manifest as malicious documents, sometimes macro-enabled Excel spreadsheets, or meticulously crafted fake websites that mimic official government portals, such as those of the Ukrainian Ministry of Foreign Affairs, Poland’s Central Bureau for Combating Cybercrime, or India’s government email service. They have even disguised malicious downloads as legitimate virus scanning utilities. More recently, the group has adopted techniques like HTML smuggling and cloud-based email evasion to bypass defenses.

A hallmark of Winter Vivern’s operations is their opportunistic exploitation of vulnerabilities in widely used enterprise software. They have exploited both known vulnerabilities, such as CVE-2022-27926 in Zimbra and CVE-2020-35730 in Roundcube, and more critically, zero-day vulnerabilities. A notable example is their exploitation of CVE-2023-5631, a zero-day cross-site scripting (XSS) vulnerability in Roundcube Webmail. This vulnerability allowed them to compromise European government email servers merely by having victims view a specially crafted email in their browser, leading to the execution of malicious JavaScript payloads. For command and control (C2) and data exfiltration, Winter Vivern typically uses HTTP and HTTPS protocols to communicate with adversary-controlled infrastructure. They also utilize PowerShell scripts for beaconing and to establish persistence, sometimes through scheduled tasks. The group demonstrates a clear focus on pre-attack reconnaissance, even using tools like the Acunetix web application vulnerability scanner hosted on their own servers to identify potential weaknesses in target environments.

Notable Campaigns

Winter Vivern has maintained a consistent operational tempo since its emergence. In early 2023, they launched campaigns targeting government websites, specifically mimicking Poland’s Central Bureau for Combating Cybercrime, the Ukraine Ministry of Foreign Affairs, and the Security Service of Ukraine, to distribute malicious downloads. Earlier, in mid-2022, they conducted credential phishing campaigns against government email services, notably targeting users of the Indian government’s email.gov.in.

December 2022 saw the group targeting individuals associated with the “Hochuzhit.com” (I Want to Live) project, a Ukrainian government initiative for Russian and Belarusian soldiers seeking to surrender, using macro-enabled Excel spreadsheets. One of their most significant campaigns, identified in October 2023, involved the exploitation of the Roundcube zero-day vulnerability (CVE-2023-5631). This particular campaign affected over 80 organizations across Europe, including government, military, and critical national infrastructure entities in Georgia, Poland, and Ukraine, as well as diplomatic missions like the Embassy of Iran in Moscow and the Embassy of Georgia in Sweden. Beyond these, the group has also utilized vulnerabilities in Zimbra to inject JavaScript payloads and steal credentials and tokens from compromised endpoints. Throughout 2024 and extending into 2025, Winter Vivern has reportedly enhanced its operational maturity, employing multi-layer staging servers, more extensive cloud-based email evasion, HTML smuggling, and targeted attacks against defense contractors and satellite communication providers, even integrating MFA bypass phishing components.

Associated Malware & Tools

Winter Vivern’s arsenal, while not exceptionally vast, is effective and purpose-built for espionage. Two key malware families are associated with the group:

  • APERETIF: This trojan is designed for automated data collection and maintaining persistence within compromised systems. It facilitates the stealthy exfiltration of sensitive data, hinting at its primary role in intelligence gathering.
  • Winter Wyvern (Unidentified JS 006): This is a malicious JavaScript script specifically crafted to target the Roundcube webmail platform. It possesses capabilities to enumerate mail folders, extract emails, and exfiltrate them to a command-and-control server via HTTP, allowing for unauthorized access to email contents.

Beyond these, Winter Vivern leverages custom PowerShell backdoors, custom loaders, and bespoke malicious JavaScript payloads, which are often tailored for specific email portals or vulnerabilities. They also use simple but effective batch scripts, frequently disguised as virus scanners, to prompt victims to download malicious payloads. The group shows a tendency to abuse legitimate Windows tools for various stages of their operations. For reconnaissance, they have utilized remotely hosted instances of the Acunetix web application vulnerability scanner, indicating a structured approach to identifying exploitable weaknesses.

Current Status

Winter Vivern remains an active and evolving threat. Observations confirm their ongoing activities as recently as late 2025 and into 2026, with a clear indication of increasing operational maturity. The group continues to pose a credible risk, particularly to government, aerospace, and chemical organizations across multiple countries. Their persistent targeting of European governments and diplomatic entities, with an unwavering focus on diplomatic communications intelligence, highlights their strategic importance to their sponsors. Despite being described as a “resource-limited” actor, Winter Vivern has consistently demonstrated that a resourceful adversary, even with modest infrastructure, can achieve significant intelligence collection by identifying and exploiting unpatched vulnerabilities and crafting convincing social engineering lures. Continuous monitoring for their evolving tactics, prompt patching of internet-facing systems, and robust credential management remain crucial defenses against this persistent threat.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call