logo

Head Mare Targets Russian Orgs with Hidden LNK Files, Ransomware

ID: b9292b4a-d379-5378-8eb4-99a23515b47a

STIX ID: report--b9292b4a-d379-5378-8eb4-99a23515b47a

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-12-11

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Cyble details a Head Mare campaign targeting Russia and Belarus that delivers the PhantomCore backdoor via a malicious LNK inside a ZIP archive (Doc.zip), leveraging social-engineering lures and exploiting the WinRAR vulnerability CVE-2023-38831; PhantomCore (C++ with Boost.Beast) fingerprints victims, connects to C2 at 45.10.247.152 (User-Agent "Boost.Beast/353"), and can download/execute additional payloads including LockBit and Babuk ransomware, with IoCs, MITRE mappings, and Yara/Sigma detection rules published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.