The group exploited a zero-day XSS vulnerability in the open-source Roundcube webmail server, used by many organizations, to target government agencies and a think tank in Europe. The vulnerability was quickly patched
Researchers of ESET, a global European leader in the cybersecurity market, during regular monitoring of Winter Vivern's cyberespionage operations, discovered that the group recently began exploiting a zero-day XSS vulnerability in the Roundcube webmail server.
In an XSS attack, malicious scripts were injected into websites believed to be trustworthy. According to telemetry data from ESET, the attack targeted Roundcube webmail servers belonging to government bodies and a think tank, all in Europe. ESET Research recommends updating Roundcube Webmail to the latest available version as soon as possible.
ESET discovered the vulnerability on October 12 and immediately reported it to Roundcube developers, who patched it and released security updates shortly after on October 14. “We would like to thank the Roundcube team for their quick response and for patching the vulnerability so quickly,” says ESET researcher Matthieu Faou, who discovered the Winter Vivern vulnerability and attacks.
“Winter Vivern is a threat to European governments due to its persistence, the massive execution of phishing campaigns, and the fact that a significant number of Internet-facing applications are not updated regularly despite being known to contain vulnerabilities,” explains Faou.
Exploitation of the CVE-2023-5631 XSS vulnerability can be done remotely by sending a specially crafted email message. “At first glance, the email does not appear to be malicious, but if we examine the HTML source code, we can see a tag for SVG graphics that contains an encoded malicious payload,” explains Faou. By sending a specially crafted email message, attackers are able to load arbitrary JavaScript code in the context of the Roundcube user's browser window. No manual interaction is required beyond viewing the message in a web browser. The final JavaScript payload can exfiltrate email messages and transfer them to the group's C&C server.
Winter Vivern is a cyberespionage group believed to have been active since at least 2020 and targets government entities in Europe and Central Asia. To compromise its goals, the group uses malicious documents, phishing websites, and a custom PowerShell backdoor. ESET considers it unlikely that Winter Vivern is linked to MoustachedBouncer, a Belarus-aligned advance group that the vendor first reported in August 2023. Winter Vivern has been targeting Zimbra and Roundcube email servers belonging to government entities since at least 2022.






