Head Mare is a pro-Ukrainian hacktivist threat group active since at least 2023 that primarily targets Russian and, to a lesser extent, Belarusian organizations. Reported victim sectors include government, manufacturing, energy, logistics, finance, construction, industry, education, science, and other state and commercial entities. The group has been associated with both disruptive and espionage-oriented intrusions, including data theft, credential harvesting, lateral movement, persistent remote access, and ransomware deployment. Head Mare is notable for combining phishing with opportunistic exploitation of public-facing applications and trusted-relationship abuse. Observed initial access methods include spearphishing with malicious archives and shortcut files, use of malicious URL files to trigger NTLM credential leakage, exploitation of WinRAR CVE-2023-38831, Microsoft Exchange ProxyLogon CVE-2021-26855, Microsoft Windows CVE-2024-43451, and exploitation of a TrueConf Server vulnerability identified as BDU:2025-10114. The group has also been observed abusing compromised contractors, valid accounts, remote desktop access, and business automation platforms to enter victim environments. The group maintains a custom malware arsenal centered on the Phantom family. Reported Head Mare tools include PhantomCore, also referred to as PhantomDL, a C++ backdoor used for remote command execution and host registration over HTTP-based JSON communications; PhantomHeart, a later backdoor used to establish SSH tunnels and increasingly implemented in PowerShell to support living-off-the-land tradecraft; PhantomJitter, used for remote command execution on servers; and PhantomProxyLite, including a PowerShell reimplementation for persistent SSH-based access. Head Mare has also been linked to CobInt in operations that showed overlap with the group Twelve. Auxiliary tooling has included tunneling and proxy utilities such as cloudflared, Gost, Localtonet, MicroSocks, RevSocks, ngrok, OpenSSH, and Sliver, alongside common post-exploitation tools such as Mimikatz, SecretsDump, ProcDump, ADRecon, PsExec, PAExec, WMIExec, SMBExec, and network scanners. Observed post-compromise behavior includes reconnaissance of hosts and Active Directory, credential dumping, creation of privileged local accounts, scheduled-task persistence, service installation, SSH reverse tunneling, selective exfiltration of documents and mail data, masquerading of tools as legitimate Windows components, artifact cleanup, and event log clearing. Head Mare has repeatedly used native Windows and PowerShell-based mechanisms to reduce detection, reflecting a growing preference for living-off-the-land techniques. In some campaigns the group deployed ransomware for final impact, including LockBit 3.0 on Windows systems and Babuk variants on network-attached storage devices. Multiple reporting streams indicate operational overlap or cooperation between Head Mare and other pro-Ukrainian actors. The strongest documented relationship is with Twelve, with shared malware, scripts, infrastructure patterns, service naming, and victimology suggesting collaboration or tool sharing in attacks on Russian entities. Coordination has also been reported with BO Team, possibly involving division of labor between initial access and follow-on operations, and collaboration has been observed with Bearlyfy. Some infrastructure and filesystem-placement overlaps have also been noted with Cloud Atlas activity, although the tradecraft of the two clusters remains differentiated. Head Mare is widely characterized as a pro-Ukrainian hacktivist actor rather than a formally confirmed state unit. Its operations align with the broader wartime cyber campaign against Russian interests and show a progression from phishing-led intrusions toward more mature, multi-stage operations that blend credential theft, stealthy persistence, tunneling, and destructive or extortionary end-stage actions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
In one incident, they exploited the Microsoft Exchange server vulnerability CVE-2021-26855 (ProxyLogon). Although patched in 2021, this vulnerability is still exploitable due to organizations using outdated operating systems and software. The attackers used ProxyLogon to execute a command to download and launch CobInt on the server.
The attackers also exploited software vulnerabilities, most commonly CVE-2023-38831 in WinRAR through phishing emails.
119 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group active against Russian organizations, motivated by disruption and public pressure.
Referenced as part of the broader Ukraine-aligned ecosystem; not specifically connected to the incidents in Bashkortostan or other dairy-sector cases by evidence in this content.
Referenced as a separate threat actor whose recent activity overlaps with Cloud Atlas infrastructure patterns; associated here with the PhantomHeart backdoor used to create SSH tunnels.
Threat group targeting Russian and Belarusian organizations, likely coordinating with BO Team, using phishing for initial access, custom malware, and exploitation of newly disclosed vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.