Threat Actor Unknown origin

Head Mare

Head Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called PhantomRAT. They have been observed executing malicious code through specially crafted RAR archives, different from previous attacks exploiting vulnerabilities. The attribution of their campaign to Ukraine is uncertain due to limited visibility inside Russian networks. PhantomCore's use of RAR archives in their attack chain has been previously observed in other threat actor groups like Forest Blizzard.

Indicators of Compromise 40

MITRE ATT&CK TTPs 14

Source Articles

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
In July 2026, the APT group Head Mare exploited two previously unknown vulnerabilities in unpatched TrueConf servers (versions 5.3.x through 5.5.5) to gain SYSTEM-level access and deploy web shells. The attackers replaced legitimate TrueConf client installers with malicious versions containing the PhantomCore backdoor, which was used to compromise video conference participants. A second backdoor, PhantomGraph, composed of SysExcSvc.dll and SysReadSvc.dll, was also deployed to establish persistence and execute commands via Base64-encoded PowerShell scripts. The group targeted Russian organizations across multiple sectors, using compromised servers and phishing to distribute malware. Kaspersky has detected the activity and provided indicators and detection rules.
securelist ·3w ago
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor Head Mare has exploited vulnerabilities in unpatched TrueConf servers to replace legitimate client installers with malicious versions delivering the PhantomCore backdoor and RAT. The attack chain involves exploiting two vulnerabilities, KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution with SYSTEM privileges, deploy a web shell, and substitute legitimate installers. The attackers also deploy a secondary backdoor, PhantomGraph, composed of two DLLs that exfiltrate data via Microsoft OneDrive and establish persistence through PowerShell commands.
hacker-news ·3w ago
Hackers breach TrueConf to trojanize client installers with backdoors
The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.
bleeping-computer ·3w ago