s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.unidentified_006

📛 Threat Title

Malware family: Unidentified JS 006 (Winter Wyvern)

Category: Unidentified JS 006 (Winter Wyvern) First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.unidentified_006`. Printable name: Unidentified JS 006 (Winter Wyvern).

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims.

  • web:cyble.com

    Unidentified JS 006 (Winter Wyvern ): A malicious script targeting the Roundcube webmail platform. Winter Wyvern can enumerate mail folders, extract emails, and send them to a command-and-control (C2) server via HTTP. Its main purpose appears to be unauthorized access to email contents, enabling espionage, identity theft, or financial fraud.

  • web:github.com

    Winter Vivern exploits zero-day vulnerability in Roundcube mail servers -- Indicators of Compromise

  • web:hunt.io

    Explore an extensive collection of the most popular malware families, including detailed descriptions, tactics, and insights into their connections with threat actors. This page serves as a comprehensive resource for security professionals and researchers, offering valuable information to understand, detect, and defend against malware threats.

  • web:malpedia.caad.fkie.fraunhofer.de

    Unidentified JS 006 (Winter Wyvern) Propose Change Actor (s): Winter Vivern A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making HTTP requests.

  • web:malware.news

    A relatively new attack group that has targeted European and Asian government organizations for several months has been exploiting a zero day XSS vulnerability in the open source Roundcube webmail server software in recent weeks. The group is known as Winter Vivern, and researchers from several organizations have been tracking its activities since at least 2020. Many of the group's targets ...

  • web:research.splunk.com

    This includes examining multiple timeout executions, scheduled task creations, screenshots, and downloading files through PowerShell, among other indicators. Why it matters The Winter Vivern malware , identified by CERT UA, is designed to download and run multiple PowerShell scripts on targeted hosts.

  • web:rewterz.com

    Analysis Summary Cybersecurity researchers have observed the Russia-linked advanced persistent threat (APT) group called Winter Vivern (aka TA473) abusing a zero-day vulnerability in Roundcube webmail software on 11 th October, 2023. The threat group was first discovered in 2021, but it has been active since at least 2020. Its main targets are European and Central Asian governments.

  • web:www.cisa.gov

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.How to use the KEV ...

  • web:www.cyfirma.com

    Deploy a unified threat management strategy - including malware detection, deep learning neural networks, and anti-exploit technology - combined with vulnerability and risk mitigation processes.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.