Winter Vivern is malware associated in the provided content with PowerShell-based collection and exfiltration activity on Windows systems. The content states that it uses a PowerShell script to capture desktop screenshots from compromised or targeted hosts and sends the captured screen images to its command-and-control server as part of its exfiltration strategy. It is also referenced in connection with PowerShell Net.WebClient UploadString activity that may be used to upload sensitive data, including screenshots or files, to an external or internal URI over a C2 channel. The described behaviors map to malicious screen capture and exfiltration over C2. Detection guidance in the content relies on Windows PowerShell Script Block Logging, specifically Event ID 4104, and looks for script blocks associated with screen capture as well as the strings "Net.webclient" and ".UploadString". High-confidence indicators from the content therefore include PowerShell-driven desktop screenshot capture, transmission of screenshots to a C2 server, and possible UploadString-based data transfer from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The following analytic identifies a potential PowerShell script that captures screen images on compromised or targeted hosts. This technique was observed in the Winter-Vivern malware, which attempts to capture desktop screens using a PowerShell script and send the images to its C2 server as part of its exfiltration strategy.
The following analytic identifies potential data exfiltration using the PowerShell net.webclient command with the UploadString method... This activity is significant as it may indicate an attempt to upload sensitive data, such as desktop screenshots or files, to an external or internal URI... Annotations ID Technique Tactic T1041 Exfiltration Over C2 Channel Exfiltration
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with using PowerShell net.webclient UploadString for potential data exfiltration of screenshots or files to a URI.
Malware observed using a PowerShell script to capture desktop screenshots on compromised or targeted hosts and exfiltrate the images to its command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.