Head Mare Intensifies Attacks On Russia With PhantomCore
ID: a4bdc91a-0341-5043-8eb5-e7820aad9b2d
STIX ID: report--a4bdc91a-0341-5043-8eb5-e7820aad9b2d
Feed Name: Cyble Blog
Threat Score
Cyble Research and Intelligence Labs (CRIL) identified a Head Mare campaign delivering a C++-compiled PhantomCore backdoor (disguised in a ZIP and executed via LNK/PowerShell) that collects system and network details and communicates with HTTP WebSocket C2 servers (Boost.Beast). The report includes technical analysis of infection and execution, multiple C2 IPs/URLs and SHA-256 IOCs, MITRE ATT&CK mappings, and notes the group's history of deploying ransomware such as LockBit and Babuk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
