ATT&CKReferencesDomainTools WinterVivern 2021

DomainTools WinterVivern 2021

Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
GroupWinter Vivern

Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads.

T1059
Command and Scripting Interpreter
GroupWinter Vivern

Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files.

T1059.001
PowerShell
GroupWinter Vivern

Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations.

T1082
System Information Discovery
GroupWinter Vivern

Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers.

T1105
Ingress Tool Transfer
GroupWinter Vivern

Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.

T1566.001
Spearphishing Attachment
GroupWinter Vivern

Winter Vivern leverages malicious attachments delivered via email for initial access activity.

T1583.001
Domains
GroupWinter Vivern

Winter Vivern registered domains mimicking other entities throughout various campaigns.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.