APERETIF is a trojan malware family associated with the Winter Vivern threat actor, also tracked as UAC-0114. CERT-UA named it based on a development PDB path found in a sample. Known APERETIF samples are PE32 executables written in Visual C++ with compilation timestamps from May 2021. The malware automates collection of victim details, maintains access, and beacons to actor-controlled infrastructure, specifically marakanas[.]com. During initial beaconing it uses PowerShell and the whoami command to request further instructions or downloads, and it also uses the HTTPS GET URI signatures.php?id=1. Winter Vivern used APERETIF in espionage campaigns targeting government organizations and at least one telecommunications organization supporting Ukraine, with targeting reported across countries including Poland and Ukraine. The group distributed APERETIF through phishing and malicious download lures, including fake virus-scanning utilities, and hosted payloads on compromised WordPress sites such as applesaltbeauty[.]com and natply[.]com. Related sample metadata includes PDB paths C:\Users\user_1\source\repos\Aperitivchick\Release\SystemProtector.pdb and C:\Users\user_1\source\repos\Aperitivchick 2\Release\SystemProtector.pdb, associated with SHA1 hashes f39b260a9209013d9559173f12fbc2bd5332c52a and a19d46251636fb46a013c7b52361b7340126ab27. One report also notes that APERETIF contains a code line described as typical of Russia-affiliated adversary behavior patterns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One malware family of recent activity is APERETIF, named by CERT-UA based on the development PDB path inside the sample... APERETIF is a trojan, automating the collection of victim details, maintaining access, and beaconing outbound the actor-controlled domain marakanas[.]com.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The group made use of compromised WordPress websites to host the malware, such as with hxxps://applesaltbeauty[.]com/wordpress/wp-includes/widgets/classwp/521734i and hxxps://natply[.]com/wordpress/wp-includes/fonts/ch/097214o serving as the download location for APERETIF during initial attack stages.
The threat actor employs various tactics, such as phishing websites, credential phishing, and deployment of malicious documents, that are tailored to the targeted organization’s specific needs.
In these attacks the threat actor made use of a macro-enabled Excel spreadsheet to infect the target.
More recently, the group has utilized a new lure technique that involves mimicking government domains to distribute malicious downloads. In early 2023, Winter Vivern targeted specific government websites by creating individual pages on a single malicious domain that closely resembled those of Poland’s Central Bureau for Combating Cybercrime, the Ukraine Ministry of Foreign Affairs, and the Security Service of Ukraine.
When the threat actor seeks to compromise the organization beyond the theft of legitimate credentials, Winter Vivern tends to rely on shared toolkits, and the abuse of legitimate Windows tools.
Specifically, Invoke-Expression cmdlet is executed, beaconing to the malicious destination of ocs-romastassec[.]com/goog_comredira3cf7ed34f8.php.
Recent campaigns demonstrate the group’s use of lures to initiate the infection process, utilizing batch scripts disguised as virus scanners to prompt downloads of malware from attacker-controlled servers.
APERETIF is a trojan, automating the collection of victim details, maintaining access, and beaconing outbound the actor-controlled domain marakanas[.]com . APERETIF also uses the signatures.php?id=1 URI through HTTPS GET requests.
The group made use of compromised WordPress websites to host the malware, such as with hxxps://applesaltbeauty[.]com/wordpress/wp-includes/widgets/classwp/521734i and hxxps://natply[.]com/wordpress/wp-includes/fonts/ch/097214o serving as the download location for APERETIF during initial attack stages.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trojan used by Winter Vivern that collects victim details, maintains access, and beacons to attacker-controlled infrastructure for further instructions or downloads. It was delivered via fake virus-scan themed lures and hosted on compromised WordPress sites.
APERETIF is a malware used by UAC-0114/Winter Vivern, likely for information stealing and exfiltration, and shows characteristics typical of Russian-affiliated threat actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.