Head Mare — APT Profile

Head Mare is a pro-Ukrainian intrusion set that has attacked organizations in Russia and Belarus since 2023, when, according to Kaspersky, it first made itself known through an account on X. Kaspersky profiled it in September 2024 as a hacktivist operation that stole data and then encrypted victims using builds from the leaked LockBit and Babuk builders, and in March 2025 tied it to the Twelve group through shared command servers and the CobInt backdoor. Its operations now run on a large custom toolset, the Phantom family, which includes the PhantomCore backdoor, the PhantomDL loader, the PhantomRemote backdoor and the PhantomGraph backdoor that uses a Microsoft OneDrive account for command and control. Kaspersky redesignated the group an APT in August 2026, citing the sophistication of its tradecraft and the absence of destructive activity rather than any state nexus, after it chained two TrueConf server flaws on an unpatched server to replace legitimate TrueConf client installers with trojanized builds served to conference participants. Vendors still disagree on the label: Positive Technologies tracks the same cluster as PhantomCore, calls it cyberespionage against Russian critical infrastructure and reported in April 2026 that the operators were in some incidents still encrypting virtual machines, servers and workstations with LockBit 3.0, while Intrinsec assessed it in November 2025 as a hacktivist intrusion set aligned with Ukraine's interests and BI.ZONE tracks it as Rainbow Hyena. F6 documented a further campaign in April 2026 in which malicious emails impersonating Russia's foreign ministry, using a North Korean delegation visit as the lure, delivered a new remote access trojan it named KermitRAT.

Also tracked as

PhantomCore, Rainbow Hyena

IntelFusions coverage (1)

Tools & malware

Vendor research

Read the full analysis on IntelFusions