← Back to all threat actors

Winter Vivern

Also known as TA473, UAC-0114
Tracked as G1035

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: TA473

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UAC-0114

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G1035

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Winter VivernCanonical Name
TA473Alias
UAC-0114Alias
G1035Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...