Activity timeline
Head Mare appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1003.001 LSASS Memory — Credential Accessobserved in 3 of 3 tracked threats
- T1033 System Owner/User Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1059.003 Windows Command Shell — Executionobserved in 3 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 3 of 3 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
- T1102.002 Bidirectional Communication — Command and Controlobserved in 2 of 3 tracked threats
- T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 2 of 3 tracked threats
- T1505.003 Web Shell — Persistenceobserved in 2 of 3 tracked threats
- T1543.003 Create or Modify System Process: Windows Service — Persistenceobserved in 2 of 3 tracked threats
- T1546.015 Component Object Model Hijacking — Persistenceobserved in 2 of 3 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 1 of 3 tracked threats
- T1005 Data from Local System — Collectionobserved in 1 of 3 tracked threats
Tracked threats
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head Mare APTCRITICAL
- Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph BackdoorsCRITICAL
- Head Mare Breaches TrueConf Servers to Trojanize Client Installers with PhantomCore/PhantomGraph BackdoorsHIGH