Unidentified JS 006 (Winter Wyvern)

First seen
2022-07-15 00:00:00
Malware type
spyware
Profile updated
2026-07-07 13:05:56

Targeted industries: government-and-public-sector media-and-entertainment

Context

A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making HTTP requests.

Reports & references

  • ESET — Winter Vivern Exploits Zero Day Vulnerability Roundcube Webmail Servers (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Unidentified 006 (report)
  • go.recordedfuture.com — Cta 2024 0217 (report)

External references