Head Mare Targets Russian Orgs with Hidden LNK Files, Ransomware
ID: b9292b4a-d379-5378-8eb4-99a23515b47a
STIX ID: report--b9292b4a-d379-5378-8eb4-99a23515b47a
Feed Name: The Cyber Express
Cyble details a Head Mare campaign targeting Russia and Belarus that delivers the PhantomCore backdoor via a malicious LNK inside a ZIP archive (Doc.zip), leveraging social-engineering lures and exploiting the WinRAR vulnerability CVE-2023-38831; PhantomCore (C++ with Boost.Beast) fingerprints victims, connects to C2 at 45.10.247.152 (User-Agent "Boost.Beast/353"), and can download/execute additional payloads including LockBit and Babuk ransomware, with IoCs, MITRE mappings, and Yara/Sigma detection rules published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
