Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Head Mare

Also known as: Fancy Bear, APT28, port 1433, Mare, Storm-2697, Bloody Wolf, SkyCloak, Awaken Likho, Bearlyfy, laboo.boo, Librarian Ghouls, Librarian Likho, Rezet, Lone Wolf, Moonshine Trickster, Clubfoot Wolf, Void Arachne, Watch Wolf, Ratopak Spider, UAC-0008, UAC-0001, Forest Blizzard, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, TA450, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers

Description

Head Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called PhantomRAT. They have been observed executing malicious code through specially crafted RAR archives, different from previous attacks exploiting vulnerabilities. The attribution of their campaign to Ukraine is uncertain due to limited visibility inside Russian networks. PhantomCore's use of RAR archives in their attack chain has been previously observed in other threat actor groups like Forest Blizzard.

Goals & Targeting

Targeted Sectors

Government
Financial services
Energy
Manufacturing
Transportation
Telecommunications
Defense
Education
Construction
Maritime
Aerospace
Critical infrastructure
Retail
Healthcare
Pharmaceutical
Aviation
Oil gas
Utilities
Chemical
Nuclear
Media
Mining
Entertainment
Legal services

Targeted Countries / Regions

RU
BY
US
UA
AE
PL
BR
IL
KZ
GB
TW
TR
RO
PK
CN
VN
JP
NG
SA
MX
ES
IT
DE
IN
NL
KR
SG
IR
AU

AI Analysis

· 1 week ago

Executive Summary

Head Mare is a suspected hacktivist threat actor group primarily targeting sectors and countries in Russia and Belarus using the PhantomRAT malware delivered via malicious RAR archives. Their activities may be linked to cyber-espionage or politically motivated attacks, though their具体 motivations and capabilities remain uncertain due to limited intelligence visibility.

Goals & Targeting

Head Mare's targeting profile suggests a focus on sectors and countries that may be perceived as adversaries or politically sensitive due to their geographic and sector-specific attacks. The group appears motivated by potential hacktivist goals, possibly linked to geopolitical tensions in Eastern Europe. Their victims are likely selected based on political or ideological grounds, targeting entities in Russia and Belarus, which could indicate a pro-Ukrainian or anti-Kremlin sentiment. The choice of malware delivery method (malicious RAR archives) implies a technical capability beyond basic hacktivism, suggesting a possible evolution toward more sophisticated cyber-espionage activities.

Enhanced Description

Head Mare is a threat actor group suspected to specialize in hacktivism, with a primary focus on targeting entities within Russia and Belarus. They are known for using a remote access malware called PhantomRAT, which they have delivered through malicious RAR archives. This method of attack differs from previous incidents involving similar malware, as it employs unique delivery mechanisms. The group's activities raise concerns about potential cyber-espionage or disruptive operations targeting critical sectors in Eastern Europe. Despite their apparent focus on Russian and Belarusian targets, the attribution of Head Mare to Ukraine remains uncertain due to the lack of visibility within Russian networks. Their use of RAR archives for malicious payloads has been observed in other threat actor groups, such as Forest Blizzard, suggesting a possible convergence in attack methods among some cyber actors.

Key Capabilities

  • PhantomRAT malware deployment
  • Exploitation via malicious RAR archives
  • Ability to remain undetected in targeted networks for extended periods
  • Possibly leveraging existing exploit techniques from other groups

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Discovery

ATT&CK Techniques

T1059
T1055
T1566

Software / Tooling

PhantomRAT
Cobalt Strike (possible reuse of attack patterns)

Campaigns & Victims

Head Mare's campaigns appear to be focused on long-term persistence and情报 collection rather than immediate payload execution. Their reliance on RAR archives suggests a methodical approach, possibly targeting specific individuals or entities within the financial or government sectors. Notable past operations include multiple waves of attacks against Russian and Belarusian targets, though exact details remain scarce due to limited intelligence sharing from affected regions.

IOC Patterns

  • Spear-phishing emails distributing malicious RAR files
  • Network traffic originating from known infrastructure linked to PhantomRAT activity
  • Presence of custom malware binaries dropped by malicious RAR payloads

Recommended Actions

  • Implement strict file type filtering for RAR archives in email communications.
  • Monitor network traffic for signs of Cobalt Strike-like activities, such as beaconing or lateral movement.
  • Conduct regular vulnerability assessments to identify and patch known exploits that may be leveraged by threat actors like Head Mare.
  • Enhance user training to recognize phishing attempts using malicious RAR files as delivery mechanisms.
  • Establish a robust incident response plan to detect and mitigate potential PhantomRAT infections.

Suggested Tags

Hacktivism
Cyber-espionage
Eastern Europe
PhantomRAT
Malware

Confidence Assessment

The analysis of Head Mare is based on limited and fragmented intelligence data. The group's sophistication level, primary motivations, and exact capabilities remain uncertain. While their use of PhantomRAT and RAR-based attacks provides some context, the lack of visibility into Russian and Belarusian networks hampers a definitive assessment of their operational scope and objectives. Further intelligence sharing and technical analysis are required to validate their specific tactics and campaign patterns.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. ics-cert.kaspersky.com — Cited by web research for: FatalRat
  3. www.kaspersky.com — Cited by web research for: pdf.lnk

Intel Summary

0

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

0

Tactics

Tags

Hacktivism
Cyber-espionage
Eastern Europe
PhantomRAT
Malware

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.