TF-MAL-js.unidentified_006
📛 Threat Title
Malware family: Unidentified JS 006 (Winter Wyvern)
Description
ThreatFox malware family `js.unidentified_006`. Printable name: Unidentified JS 006 (Winter Wyvern).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims.
-
web:cyble.com
Unidentified JS 006 (Winter Wyvern ): A malicious script targeting the Roundcube webmail platform. Winter Wyvern can enumerate mail folders, extract emails, and send them to a command-and-control (C2) server via HTTP. Its main purpose appears to be unauthorized access to email contents, enabling espionage, identity theft, or financial fraud.
-
web:github.com
Winter Vivern exploits zero-day vulnerability in Roundcube mail servers -- Indicators of Compromise
-
web:hunt.io
Explore an extensive collection of the most popular malware families, including detailed descriptions, tactics, and insights into their connections with threat actors. This page serves as a comprehensive resource for security professionals and researchers, offering valuable information to understand, detect, and defend against malware threats.
-
web:malpedia.caad.fkie.fraunhofer.de
Unidentified JS 006 (Winter Wyvern) Propose Change Actor (s): Winter Vivern A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making HTTP requests.
-
web:malware.news
A relatively new attack group that has targeted European and Asian government organizations for several months has been exploiting a zero day XSS vulnerability in the open source Roundcube webmail server software in recent weeks. The group is known as Winter Vivern, and researchers from several organizations have been tracking its activities since at least 2020. Many of the group's targets ...
-
web:research.splunk.com
This includes examining multiple timeout executions, scheduled task creations, screenshots, and downloading files through PowerShell, among other indicators. Why it matters The Winter Vivern malware , identified by CERT UA, is designed to download and run multiple PowerShell scripts on targeted hosts.
-
web:rewterz.com
Analysis Summary Cybersecurity researchers have observed the Russia-linked advanced persistent threat (APT) group called Winter Vivern (aka TA473) abusing a zero-day vulnerability in Roundcube webmail software on 11 th October, 2023. The threat group was first discovered in 2021, but it has been active since at least 2020. Its main targets are European and Central Asian governments.
-
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.How to use the KEV ...
-
web:www.cyfirma.com
Deploy a unified threat management strategy - including malware detection, deep learning neural networks, and anti-exploit technology - combined with vulnerability and risk mitigation processes.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.