Pro-Ukraine BO Team and Head Mare hackers appear to team up in attacks against Russia
ID: 4b41d257-391c-5282-af8a-542d33f0c2f7
STIX ID: report--4b41d257-391c-5282-af8a-542d33f0c2f7
Feed Name: The Record from Recorded Future News
Threat Score
BO Team and Head Mare are reported to be coordinating cyber operations against Russian and Belarusian targets, with Kaspersky identifying overlapping infrastructure and toolsets; BO Team has shifted toward covert espionage and in Q1 2026 targeted 20 organizations across manufacturing, telecommunications, and oil & gas using phishing and backdoors (BrockenDoor, Remcos, DarkGate) while Head Mare employs custom malware (PhantomDL, PhantomCore).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
