Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
GroupWinter Vivern | Winter Vivern PowerShell scripts execute `whoami` to identify the executing user. |
| T1036 Masquerading |
GroupWinter Vivern | Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns. |
| T1036.004 Masquerade Task or Service |
GroupWinter Vivern | Winter Vivern has distributed malicious scripts and executables mimicking virus scanners. |
| T1056.003 Web Portal Capture |
GroupWinter Vivern | Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information. |
| T1059.003 Windows Command Shell |
GroupWinter Vivern | Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools. |
| T1071.001 Web Protocols |
GroupWinter Vivern | Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity. |
| T1204.001 Malicious Link |
GroupWinter Vivern | Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution. |
| T1566.001 Spearphishing Attachment |
GroupWinter Vivern | Winter Vivern leverages malicious attachments delivered via email for initial access activity. |
| T1583.003 Virtual Private Server |
GroupWinter Vivern | Winter Vivern used adversary-owned and -controlled servers to host web vulnerability scanning applications. |
| T1584.006 Web Services |
GroupWinter Vivern | Winter Vivern has used compromised WordPress sites to host malicious payloads for download. |
| T1595.002 Vulnerability Scanning |
GroupWinter Vivern | Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.