Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1035
MITRE ATT&CK Group

Winter Vivern (G1035)

TA473UAC-0114
ShareXLinkedInRedditHN

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.(Citation: DomainTools WinterVivern 2021)(Citation: SentinelOne WinterVivern 2023)(Citation: CERT-UA WinterVivern 2023)(Citation: ESET WinterVivern 2023)(Citation: Proofpoint WinterVivern 2023)

▪Techniques used (27)

T1059Command and Scripting InterpreterT1071.001Web ProtocolsT1056.003Web Portal CaptureT1033System Owner/User DiscoveryT1583.003Virtual Private ServerT1059.007JavaScriptT1566.001Spearphishing AttachmentT1036.004Masquerade Task or ServiceT1113Screen CaptureT1189Drive-by CompromiseT1119Automated CollectionT1140Deobfuscate/Decode Files or InformationT1020Automated ExfiltrationT1105Ingress Tool TransferT1190Exploit Public-Facing ApplicationT1595.002Vulnerability ScanningT1041Exfiltration Over C2 ChannelT1053.005Scheduled TaskT1584.006Web ServicesT1036MasqueradingT1583.001DomainsT1082System Information DiscoveryT1059.003Windows Command ShellT1204.001Malicious LinkT1083File and Directory DiscoveryT1114.001Local Email CollectionT1059.001PowerShell
G1035on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.