Skip to main content

Winter Vivern APT Blasts Webmail Zero-Day Bug With One-Click Exploit


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

A campaign targeting European governmental organizations and a think tank shows consistency from the low-profile threat group, which has ties to Belarus and Russia.

 

October 25, 2023 By Elizabeth Montalbano

 

Low-profile threat group Winter Vivern has been exploiting a zero-day flaw in Roundcube Webmail servers with a malicious email campaign targeting governmental organizations and a think tank in Europe that requires only that a user view a message.

Earlier this month, researchers at ESET Research observed the group sending a specially crafted email message that loads an arbitrary JavaScript code in the context of the Roundcube user's browser window to exploit a newly discovered cross-site scripting (XSS) flaw tracked as CVE-2023-5631. The one-click exploit requires no manual interaction on the part of the user other than viewing the message in a Web browser, the researchers reported in a blog post published Oct. 25.

 

>> Full Article <<

0 replies

Be the first to reply!

Reply