Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers
ID: f055eb93-cbe3-507c-9895-e3103a3e4194
STIX ID: report--f055eb93-cbe3-507c-9895-e3103a3e4194
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET Research details how the Winter Vivern APT exploited a zero-day XSS (CVE-2023-5631) in Roundcube Webmail via crafted email SVGs to inject JavaScript, load a loader (checkupdate.js) from recsecas.com, and exfiltrate emails to the actor-controlled C2; targeted European government and think-tank servers were observed, patches and a CVE were issued, and the report includes IoCs and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
