Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.6
group
Winter Vivern G1035
- Created
- 29 July 2024
- Last modified
- 31 July 2026
- Aliases
- Winter Vivern · TA473 · UAC-0114
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.[1][2][3][4][5]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1035
Winter Vivern PowerShell scripts execute whoami to identify the executing user.7
Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns.8
Winter Vivern has distributed malicious scripts and executables mimicking virus scanners.9
Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.10
Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads.11
Standing G1035
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
61st percentile · 61% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
73rd percentile · 73% of 176 ATT&CK groups have this many tactics spanned or fewer.
9th percentile · 91% of 176 ATT&CK groups have more tools and malware.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
52nd percentile · 52% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G1035
1271 distinct rules cover the 27 techniques recorded for this group. The 1409 technique-to-rule mappings resolve to 1271 distinct rules, because one rule can cover several techniques. 872 Sigma · 399 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org