ATT&CKReferencesSentinelOne WinterVivern 2023

SentinelOne WinterVivern 2023

Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
GroupWinter Vivern

Winter Vivern PowerShell scripts execute `whoami` to identify the executing user.

T1036
Masquerading
GroupWinter Vivern

Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns.

T1036.004
Masquerade Task or Service
GroupWinter Vivern

Winter Vivern has distributed malicious scripts and executables mimicking virus scanners.

T1056.003
Web Portal Capture
GroupWinter Vivern

Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information.

T1059.003
Windows Command Shell
GroupWinter Vivern

Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools.

T1071.001
Web Protocols
GroupWinter Vivern

Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.

T1204.001
Malicious Link
GroupWinter Vivern

Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution.

T1566.001
Spearphishing Attachment
GroupWinter Vivern

Winter Vivern leverages malicious attachments delivered via email for initial access activity.

T1583.003
Virtual Private Server
GroupWinter Vivern

Winter Vivern used adversary-owned and -controlled servers to host web vulnerability scanning applications.

T1584.006
Web Services
GroupWinter Vivern

Winter Vivern has used compromised WordPress sites to host malicious payloads for download.

T1595.002
Vulnerability Scanning
GroupWinter Vivern

Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.