WINTER VIVERN
G1035
UNKNOWN (RUSSIA-ALIGNED)
TA473
Threat IntelligenceAPTFebruary 11, 2026

Winter Vivern Threat Profile

Russia-aligned group exploiting Zimbra and Roundcube zero-days to target European government and NATO-aligned diplomatic entities.

Russia-aligned group exploiting Zimbra and Roundcube zero-days to target European government and NATO-aligned diplomatic entities. This profile is mapped to MITRE ATT&CK G1035 and covers attribution, tooling, targeting, and defensive recommendations based on observed campaigns.

Overview & Attribution

Winter Vivern (also tracked as TA473, UAC-0114) is a threat group attributed to Unknown (Russia-aligned). The group primarily targets NATO, European government, diplomatic for intelligence collection and operational objectives aligned with state interests.

MITRE ATT&CK Reference

This group is tracked as G1035 in the MITRE ATT&CK framework. All techniques referenced in this report are mapped to ATT&CK for consistent threat modeling and detection engineering.

Arsenal & Tools

Known tools and malware associated with Winter Vivern include:

Targeting & Operations

Winter Vivern operations focus on NATO, European government, diplomatic. The group typically gains initial access through spear-phishing, exploitation of public-facing applications, or strategic web compromises before deploying custom implants for persistent access and data exfiltration.

Targeting Advisory

Organizations in the NATO sector should treat Winter Vivern as a relevant threat and validate their detection coverage against the MITRE ATT&CK techniques listed below.

MITRE ATT&CK Mapping

Key techniques observed in Winter Vivern operations:

Technique IDTechnique NameTactical Context
T1190T1190Observed in Winter Vivern campaigns
T1059.007T1059.007Observed in Winter Vivern campaigns
T1114.002T1114.002Observed in Winter Vivern campaigns
T1566.002T1566.002Observed in Winter Vivern campaigns

Full ATT&CK mapping: https://attack.mitre.org/groups/G1035/

Notable Campaigns

This threat group has been active in operations targeting NATO, European government, diplomatic. Security researchers have documented campaigns involving Zimbra/Roundcube exploits and other tools deployed against organizations in multiple countries. Attribution confidence varies by campaign, but consistent infrastructure and TTP overlap links activity to Unknown (Russia-aligned)-nexus operations.

Detection & Defense

Recommended defensive measures against Winter Vivern:

How Mjolnir Security Can Help

Defend Against Winter Vivern

Mjolnir Security provides tailored threat intelligence, detection engineering, and incident response services to help organizations defend against Unknown (Russia-aligned)-nexus threat actors.

Threat Intelligence Detection Engineering Incident Response Red Team Assessment Threat Hunting

Contact us: mjolnirsecurity.com

Written by: Mjolnir Security  |  Published: February 11, 2026