Cyber Threat Report: 'Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages'
Report Author | DomainTools |
---|---|
Publication Date | 2021-04-27 |
Original Reporting | Source |
Related Intrusion Sets | Winter Vivern |
Victim Sectors | National Government |
This report by DomainTools researchers identifies a cyber threat group they call "Winter Vivern". The report describes malicious Excel macros used by the group to drop a PowerShell script to initiate command-and-control (C2) communications. The activity dates back to at least December 2020.
Cyber Threat Graph Context
Explore how this report relates to the wider threat graph