← Threat Actors & APT Groups

Head Mare

Every article that identifies Head Mare as responsible for or connected to reported activity.

MalwareKaspersky Securelist·1 week ago

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Kaspersky researchers have identified that the Head Mare APT group is exploiting unpatched vulnerabilities in TrueConf servers to distribute the PhantomCore and PhantomGraph backdoors to video conference participants. The attack leverages compromised TrueConf software installers to deliver these malicious payloads to target systems. This campaign highlights the risks posed by unpatched collaboration tools and their potential use as infection vectors by sophisticated threat actors.