Winter Vivern is a cyberespionage threat actor tracked under aliases including TA473 and UAC-0114. The group is widely assessed as a pro-Russian, likely state-aligned actor whose operations support the interests of Russia and Belarus. Since at least 2021, it has conducted espionage-focused campaigns primarily against government, diplomatic, military, and other high-value organizations, with targeting observed across Europe and beyond, including entities linked to Ukraine and NATO-aligned interests. Reported victims have included ministries of foreign affairs, government agencies, diplomats, military personnel, and at least one telecommunications organization supporting Ukraine. Winter Vivern is notable for achieving intelligence collection objectives with comparatively simple but adaptable tradecraft. The actor has repeatedly targeted webmail and collaboration platforms, including Zimbra and Roundcube, and has exploited cross-site scripting and related webmail vulnerabilities to steal emails, credentials, session data, contacts, and other mailbox contents. In one documented pattern, the group used malicious JavaScript payloads delivered through exploited webmail interfaces to enumerate folders and messages and exfiltrate data from victim accounts. The actor has also been associated with reflected XSS exploitation against Zimbra webmail portals to compromise accounts belonging to government and diplomatic targets. Beyond server-side and webmail exploitation, Winter Vivern has relied heavily on spearphishing, credential phishing, and malicious documents for initial access. Its lures have impersonated government themes and trusted institutions, and it has used phishing pages designed to mimic official services. Document-based infection chains have included XLM 4.0 macros and macro-enabled spreadsheets that pass execution to PowerShell. The group has also distributed Windows batch scripts disguised as benign utilities such as virus scanners in order to trigger follow-on payload retrieval using built-in system tools. Observed tooling includes the APERETIF trojan as well as lightweight script-based loaders and post-compromise collection components. Winter Vivern commonly uses PowerShell and batch scripting during execution and installation, including Invoke-Expression-based download-and-execute behavior. Its scripts perform basic host profiling, including execution of whoami and related victim information gathering, then transmit collected data to command-and-control infrastructure. The actor has also used Base64-encoded payloads and obfuscated script content as part of staging and execution. Collection activity is focused on espionage-relevant data. Winter Vivern has deployed PowerShell scripts that recursively scan victim systems for files of interest and exfiltrate identified content over HTTP or HTTPS. The group has also used malicious JavaScript in webmail compromises to harvest mailbox data directly from targeted accounts. Command and control and exfiltration have been observed over standard web protocols, helping the actor blend into normal network traffic. Winter Vivern has shown opportunistic infrastructure use, including compromised websites for malware hosting, while maintaining a relatively restrained and selective targeting profile compared with larger Russian intelligence-linked groups. Its operations consistently align with intelligence collection rather than disruptive or financially motivated objectives. Overall, Winter Vivern is best characterized as a resource-constrained but effective espionage actor specializing in phishing, webmail exploitation, script-based intrusion chains, and theft of communications data from government and geopolitical targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
ESET Research ... found that the group began exploiting a zero-day XSS vulnerability in the Roundcube Webmail server ... assigned CVE-2023-5631 ... affecting the server-side script rcube_washtml.php ... patched on October 14th, 2023 ... security updates ... (1.6.4, 1.5.5, and 1.4.15).
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
... different vulnerability than CVE-2020-35730 ... the group exploited CVE-2020-35730, another XSS vulnerability in Roundcube, in August and September 2023. Note that Sednit (also known as APT28) is exploiting this old XSS vulnerability in Roundcube as well ...
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously exploited similar Zimbra flaws to steal emails and credentials from government and military organizations.
Used a reflected XSS exploit against Zimbra webmail portals to steal emails from NATO-aligned organizations and individuals.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed in the detection annotations as a threat actor associated with this analytic context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.