Cyber Threat Report: 'Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages'

Report Author DomainTools
Publication Date 2021-04-27
Original Reporting Source
Related Intrusion Sets Winter Vivern
Victim Sectors National Government

This report by DomainTools researchers identifies a cyber threat group they call "Winter Vivern". The report describes malicious Excel macros used by the group to drop a PowerShell script to initiate command-and-control (C2) communications. The activity dates back to at least December 2020.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph