Threadlinqs IntelligenceStart free

Threat actorUkraineTracked since 2026-08

Head Mare

As of 2026-08-23, Head Mare is a Ukraine-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning vulnerability, apt, supply chain. ATT&CK coverage spans 35 techniques across 12 tactics in 3 of 3 tracked threats. Most-observed techniques: T1003.001 (LSASS Memory), T1033 (System Owner/User Discovery), T1059.003 (Windows Command Shell).

Tracked threats
32 critical · 1 high
First seen
2026-08-08
Last seen
2026-08-20
ATT&CK techniques
35across 3 of 3 threats
Related CVEs
2Referenced by its activity
Attribution
UkraineNation or origin
Nation: Ukraine · 3 tracked threat(s) · Categories: VULNERABILITY, APT, SUPPLY_CHAIN

Activity timeline

Head Mare appears in 3 tracked threats between and .

ATT&CK techniques observed

35 techniques observed across 3 of 3 tracked threats · Command and Control (6), Execution (6), Persistence (6), Stealth (formerly Defense Evasion) (4), Credential Access (2), Discovery (2)
  • T1003.001 LSASS Memory — Credential Accessobserved in 3 of 3 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 3 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 3 of 3 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
  • T1102.002 Bidirectional Communication — Command and Controlobserved in 2 of 3 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 2 of 3 tracked threats
  • T1505.003 Web Shell — Persistenceobserved in 2 of 3 tracked threats
  • T1543.003 Create or Modify System Process: Windows Service — Persistenceobserved in 2 of 3 tracked threats
  • T1546.015 Component Object Model Hijacking — Persistenceobserved in 2 of 3 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 1 of 3 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 3 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked Head Mare activity