Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: TA473, UAC-0114
27
techniques
0
software
11,772
corpus matches
profile
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.
read this carefully
11,772 corpus matches is not attribution
That count is indicators which exhibit techniques Winter Vivern is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+15 more techniques
showing 30 of 11,772
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.