Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
GroupWinter Vivern | Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads. |
| T1059 Command and Scripting Interpreter |
GroupWinter Vivern | Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files. |
| T1059.001 PowerShell |
GroupWinter Vivern | Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations. |
| T1082 System Information Discovery |
GroupWinter Vivern | Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers. |
| T1105 Ingress Tool Transfer |
GroupWinter Vivern | Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads. |
| T1566.001 Spearphishing Attachment |
GroupWinter Vivern | Winter Vivern leverages malicious attachments delivered via email for initial access activity. |
| T1583.001 Domains |
GroupWinter Vivern | Winter Vivern registered domains mimicking other entities throughout various campaigns. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.