# Head Mare

> As of 2026-08-23, Head Mare is a Ukraine-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning vulnerability, apt, supply chain. ATT&CK coverage spans 35 techniques across 12 tactics in 3 of 3 tracked threats. Most-observed techniques: T1003.001 (LSASS Memory), T1033 (System Owner/User Discovery), T1059.003 (Windows Command Shell).

- **Nation:** Ukraine
- **Tracked threats:** 3
- **Categories:** VULNERABILITY, APT, SUPPLY_CHAIN
- **As of:** 2026-08-23

## ATT&CK techniques observed

35 techniques observed across 3 of 3 tracked threats. Tactics: Command and Control (6), Execution (6), Persistence (6), Stealth (formerly Defense Evasion) (4), Credential Access (2), Discovery (2).

- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 3 of 3 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1059.003](https://intel.threadlinqs.com/technique/T1059.003) Windows Command Shell — Execution — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 3 of 3 tracked threats
- [T1572](https://intel.threadlinqs.com/technique/T1572) Protocol Tunneling — Command and Control — observed in 3 of 3 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 3 tracked threats
- [T1102.002](https://intel.threadlinqs.com/technique/T1102.002) Bidirectional Communication — Command and Control — observed in 2 of 3 tracked threats
- [T1195.002](https://intel.threadlinqs.com/technique/T1195.002) Compromise Software Supply Chain — Initial Access — observed in 2 of 3 tracked threats
- [T1505.003](https://intel.threadlinqs.com/technique/T1505.003) Web Shell — Persistence — observed in 2 of 3 tracked threats
- [T1543.003](https://intel.threadlinqs.com/technique/T1543.003) Create or Modify System Process: Windows Service — Persistence — observed in 2 of 3 tracked threats
- [T1546.015](https://intel.threadlinqs.com/technique/T1546.015) Component Object Model Hijacking — Persistence — observed in 2 of 3 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 3 tracked threats

## Tracked threats

- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head Mare APT](https://intel.threadlinqs.com/threat/TL-2026-2087) — CRITICAL
- [Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoors](https://intel.threadlinqs.com/threat/TL-2026-1982) — CRITICAL
- [Head Mare Breaches TrueConf Servers to Trojanize Client Installers with PhantomCore/PhantomGraph Backdoors](https://intel.threadlinqs.com/threat/TL-2026-1945) — HIGH

## Related CVEs

2 CVEs referenced by tracked Head Mare activity.

- [CVE-2026-72530](https://intel.threadlinqs.com/cve/CVE-2026-72530)
- [CVE-2026-72529](https://intel.threadlinqs.com/cve/CVE-2026-72529)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Head%20Mare
