Winter Vivern is a Russia-linked cyber-espionage threat actor also tracked as TA473 and UAC-0114. The group has targeted government personnel and institutions in Europe and Asia, including diplomatic and NATO-aligned organizations. Its operations are primarily oriented toward intelligence collection, with a demonstrated interest in organizational email systems and government communications. Winter Vivern has conducted spearphishing campaigns using malicious Excel documents with Excel 4.0 macros to execute PowerShell-based payloads. Observed tradecraft includes victim-tailored government-themed lures, staged payload delivery, command-and-control polling, and scheduled-task persistence. The actor has also targeted Zimbra webmail deployments, including exploitation of a reflected cross-site scripting vulnerability in 2023 to steal email from NATO-aligned individuals and organizations. Winter Vivern has used credential phishing, PowerShell, backdoors, and exploitation of public-facing applications in support of its espionage activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
16 CVEs this actor has used in observed campaigns. 16 of them exploited in the wild.
Typical compromise chain ... https://<victim’s Zimbra domain>/public/error.jsp?errCode= ... CVE-2022-27926 ... Government staff Europe and Asia ... Phishing for credentials Zimbra Winter Vivern
ESET Research ... found that the group began exploiting a zero-day XSS vulnerability in the Roundcube Webmail server ... assigned CVE-2023-5631 ... affecting the server-side script rcube_washtml.php ... patched on October 14th, 2023 ... security updates ... (1.6.4, 1.5.5, and 1.4.15).
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
... different vulnerability than CVE-2020-35730 ... the group exploited CVE-2020-35730, another XSS vulnerability in Roundcube, in August and September 2023. Note that Sednit (also known as APT28) is exploiting this old XSS vulnerability in Roundcube as well ...
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
11 more CVEs tied to this actor tracked in Mallory.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Winter Vivern is listed in the detection's annotations for MITRE ATT&CK technique T1059 (Command and Scripting Interpreter).
Listed as an annotated threat actor associated with the Socat detection; no actor-specific activity is described.
Included only as an annotated threat-actor association; no actor-specific activity is described.
Historically linked to exploitation of Zimbra vulnerabilities and targeting military and diplomatic intelligence; the article does not attribute the current CVE-2026-73570 compromises to this group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.