logo

Head Mare and Twelve join forces to attack Russian entities

ID: e99d352d-76d2-5102-ae68-b4bcaa07980c

STIX ID: report--e99d352d-76d2-5102-ae68-b4bcaa07980c

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-03-13

Date Updated: 2026-04-29

Author: Kaspersky

...
...

This report analyzes September 2024 attacks on Russian companies by hacktivist group Head Mare, documenting use of known and new tools (PhantomJitter, CobInt), exploitation vectors (phishing, CVE-2021-26855 ProxyLogon, CVE-2023-38831), tunneling and persistence techniques (cloudflared, Gost, Localtonet, NSSM), credential theft and AD dumping, data exfiltration with rclone, and final-stage encryption using LockBit 3.0 and Babuk; overlaps in tools and C2 infrastructure (360nvidia.com, 45.156.27.115) suggest collaboration with the Twelve group and provide a set of IOCs and mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.