logo

Head Mare: adventures of a unicorn in Russia and Belarus

ID: e748a426-290c-5966-a6b8-b25bab2c9ae2

STIX ID: report--e748a426-290c-5966-a6b8-b25bab2c9ae2

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2024-09-02

Date Updated: 2026-04-29

Author: Kaspersky

...
...

Kaspersky documents the activities of the hacktivist group Head Mare, which targets organizations in Russia and Belarus using phishing that exploits CVE-2023-38831 (WinRAR) to deliver custom malware (PhantomDL/PhantomCore) and publicly available tools (Sliver, Mimikatz, ngrok), culminating in LockBit (Windows) and Babuk (ESXi) ransomware deployment; the report provides TTPs, persistence and evasion methods, C2 infrastructure analysis, and extensive IOCs (hashes, IPs, file paths, URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.