Skip to content

Incidents attributed to:

Winter Vivern

Winter Vivern is a cyberespionage group first revealed by DomainTools in 2021.

Winter Vivern is a cyberespionage group first revealed by DomainTools in 2021. It is thought to have been active since at least 2020 and it targets governments in Europe and Central Asia. To compromise its targets, the group uses malicious documents, phishing websites, and a custom PowerShell backdoor.

Also known as

UAC-0114, TA473, TAG-70, TA-473.

References


Actor metadata imported from Malpedia (Fraunhofer FKIE).