Winter Vivern is investigated by SentinelLabs with observations from the Polish CBZC and Ukraine CERT, revealing a new wave of espionage campaigns linked to pro-Russian objectives. The APT targets governments and private entities globally, using tailored lures and loaders to gain unauthorized access. #WinterVivern #APERETIF #Hochuzhit #Marakanas #Acunetix #PolandCBZC #UkraineCERT
Keypoints
- Winter Vivern is a pro-Russian-aligned APT conducting global espionage against government and private-sector targets.
- The campaigns leverage phishing websites, credential phishing, and deployment of malicious documents to gain access and deploy loaders.
- Lures include government-domain mimicry and fake virus scanner loaders, with targeting across Poland, Ukraine, and other nations.
- The APERETIF trojan, PowerShell beacons, and compromised WordPress sites are used to deliver and control malware.
- The group uses macros and PowerShell (Invoke-Expression) and batch scripts to trigger downloads and execution.
- Targets span multiple countries (Lithuania, India, Vatican, Slovakia, Poland, Ukraine) and include private telecoms supporting Ukraine.
MITRE Techniques
- [T1566] Phishing – The threat actor used phishing websites and credential phishing, including government-domain mimicry to prompt downloads and capture credentials. ‘The threat actor employs various tactics, such as phishing websites, credential phishing, and deployment of malicious documents, that are tailored to the targeted organization’s specific needs.’
- [T1204.002] User Execution: Malicious File – Macro-enabled Excel used to infect targets. ‘In these attacks the threat actor made use of a macro-enabled Excel spreadsheet to infect the target.’
- [T1059.001] PowerShell – PowerShell invoked via a macro and used to beacon to a remote URL. ‘PowerShell is called through a macro. Specifically, Invoke-Expression cmdlet is executed, beaconing to the malicious destination of ocs-romastassec[.]com/goog_comredira3cf7ed34f8.php.’
- [T1059.003] Windows Command Shell – Batch scripts disguised as virus scanners prompt malware downloads. ‘utilizing batch scripts disguised as virus scanners to prompt downloads of malware from attacker-controlled servers.’
- [T1189] Drive-by Compromise – Attackers mimic government domains to distribute malicious downloads via compromised pages. ‘targeted government websites by creating individual pages on a single malicious domain that closely resembled those of Poland’s Central Bureau for Combating Cybercrime, the Ukraine Ministry of Foreign Affairs, and the Security Service of Ukraine.’
- [T1105] Ingress Tool Transfer – Beaconing outbound for further instructions and/or downloads from attacker-controlled servers. ‘beaconing outbound for further instructions and/or downloads.’
- [T1190] Exploit Public-Facing Application – Exploiting application vulnerabilities to compromise targets or staging servers. ‘exploiting application vulnerabilities to compromise specific targets or staging servers.’
Indicators of Compromise
- [Domain] bugiplaysec[.]com – domain associated with attacker infrastructure
- [Domain] marakanas[.]com – domain used for malware delivery and beaconing
- [Domain] mfa_it_sec@outlook[.]com – domain/alias observed in the actor’s activity
- [Domain] ocs-romastassec[.]com – domain used for C2/downloads
- [Domain] ocspdep[.]com – domain used in malicious operations
- [Domain] security-ocsp[.]com – domain used in campaigns
- [Domain] troadsecow[.]com – domain tied to infrastructure
- [URL] https://applesaltbeauty[.]com/wordpress/wp-includes/widgets/classwp/521734i – malicious hosting page
- [URL] https://marakanas[.]com/Kkdn7862Jj6h2oDASGmpqU4Qq4q4.php – payload delivery URL
- [URL] https://natply[.]com/wordpress/wp-includes/fonts/ch/097214o – download host
- [URL] https://ocs-romastassec[.]com/goog_comredira3cf7ed34f8.php – payload/command fetch
- [IP] 176.97.66[.]57 – observed infrastructure IP
- [IP] 179.43.187[.]175 – observed infrastructure IP
- [IP] 179.43.187[.]207 – observed infrastructure IP
- [IP] 195.54.170[.]26 – observed infrastructure IP
- [IP] 80.79.124[.]135 – observed infrastructure IP
- [File SHA1] 0fe3fe479885dc4d9322b06667054f233f343e20 – file hash associated with samples
- [File SHA1] 83f00ee38950436527499769db5c7ecb74a9ea41 – file hash
- [File SHA1] a19d46251636fb46a013c7b52361b7340126ab27 – file hash
- [File SHA1] a574c5d692b86c6c3ee710af69fccbb908fe1bb8 – file hash
- [File SHA1] c7fa6727fe029c3eaa6d9d8bd860291d7e6e3dd0 – file hash
- [File SHA1] f39b260a9209013d9559173f12fbc2bd5332c52a – file hash
Read more: https://www.sentinelone.com/labs/winter-vivern-uncovering-a-wave-of-global-espionage/