logo

Winter Vivern (TAG-70 / UAC-0114 / TA473): A Persistent Eastern European Cyber-Espionage Threat Targeting NATO and EU Governments

ID: cc32975c-6bc6-5a3f-a004-7f7a89d78a4d

STIX ID: report--cc32975c-6bc6-5a3f-a004-7f7a89d78a4d

Feed Name: Brandefense Blog

Threat Score
90/100

Date Published: 2026-02-20

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

Winter Vivern (TAG-70/UAC-0114/TA473) is a Russia-aligned, state-sponsored APT active since 2020 that conducts sustained espionage against NATO, EU and Ukrainian government, military, diplomatic and telecom targets using spear-phishing, credential-harvesting portals, web shells, PowerShell loaders and Zimbra exploits; the report details their TTPs, multi-year campaign activity and recommends hardening email infrastructure, continuous vulnerability management, advanced phishing detection and stronger authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.