Unidentified JS 006 (Winter Wyvern)
- First seen
- 2022-07-15 00:00:00
- Malware type
- spyware
- Profile updated
- 2026-07-07 13:05:56
Targeted industries: government-and-public-sector media-and-entertainment
Context
A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making HTTP requests.
Reports & references
- ESET — Winter Vivern Exploits Zero Day Vulnerability Roundcube Webmail Servers (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Unidentified 006 (report)
- go.recordedfuture.com — Cta 2024 0217 (report)