Executive Summary
Head Mare began in 2023 as a self-declared hacktivist collective announcing itself on X, claiming attacks against Russian and Belarusian organisations in solidarity with Ukraine. For its first two years of documented activity, Kaspersky’s telemetry placed it firmly in the “opportunistic, noisy, ransomware-as-disruption” bracket — a group that broke in via a WinRAR flaw, deployed leaked LockBit and Babuk builders, and publicised its victims on social media for propaganda value as much as extortion. In August 2026, Kaspersky formally reclassified Head Mare as an advanced persistent threat. The trigger was a campaign, first observed in July 2026, that exploited two previously unknown vulnerabilities in TrueConf Server — a videoconferencing platform used across Russian government and industrial organisations — to gain unauthenticated, SYSTEM-level code execution, trojanise the platform’s own client installers, and operate a two-stage backdoor set (PhantomCore and PhantomGraph) that used Microsoft OneDrive accounts as its command-and-control channel.
The reclassification matters beyond taxonomy. It documents a pattern seen elsewhere in the pro-Ukraine hacktivist ecosystem: groups that started with commodity ransomware and leaked exploit code maturing into operators capable of finding and weaponising their own zero-days, building custom sandbox-escape chains, and abusing legitimate cloud services to blend malicious traffic into normal enterprise network activity. For defenders in communications, transport, energy, and industrial sectors — inside Russia and Belarus today, but potentially anywhere TrueConf or similar on-premises videoconferencing platforms are deployed tomorrow — the campaign is a concrete illustration of how quickly a hacktivist group’s capability ceiling can rise once it has motive, time, and access to a mature underground tooling supply.
Threat Actor Profile: From Hacktivist Noise to APT
Head Mare’s origin story is unusual for a group now carrying an APT designation. Kaspersky’s original September 2024 writeup described a collective that surfaced publicly on social media in 2023, explicitly framing its operations as retaliation tied to the Russo-Ukrainian conflict, and claimed at least nine victims spanning government, transportation, energy, manufacturing, and entertainment organisations, all located in Russia and Belarus. Unlike purely destructive hacktivist crews that simply wipe or deface, Head Mare’s model from the start combined disruption with extortion: it deployed a version of LockBit generated from the leaked 2022 LockBit 3.0 builder against Windows hosts and a Babuk variant using X25519, SHA-256, and Sosemanuk encryption against Linux and ESXi hosts, while also publishing stolen data and victim names for reputational damage.
Initial access in the group’s earlier campaigns relied on phishing emails carrying malicious RAR archives that exploited CVE-2023-38831 in WinRAR — a path-traversal-style flaw that lets an attacker disguise executable content inside an archive so that opening what looks like a document (for example, a file with a double extension like “contract.pdf.exe”) silently runs attacker code. Supporting tradecraft included the Sliver C2 framework, ngrok and rsockstun for tunnelling, Mimikatz for credential harvesting, and a custom password-extraction tool. The group also fielded two homegrown Go-based tools, PhantomDL and PhantomCore (sometimes referred to as PhantomRAT), likely obfuscated with the Garble compiler-level obfuscator, used for reconnaissance and establishing C2 channels. Kaspersky has separately documented Head Mare coordinating operations with at least one other pro-Ukraine hacktivist cluster, Twelve, against shared Russian targets — evidence of an informal division of labour or infrastructure-sharing arrangement within that ecosystem rather than a single monolithic actor.
The July 2026 TrueConf campaign represents a step change from that baseline. Rather than relying on a disclosed, patched vulnerability and a phishing lure, Head Mare found and exploited two flaws that were unknown to the vendor at the time of use, chained them into a full compromise of a production communications server, and used that foothold to distribute trojanised software to every organisation relying on the compromised server for client downloads — a supply-chain pattern more associated with state-nexus espionage operators than social-media hacktivist collectives.
Technical Analysis: The TrueConf Exploitation Chain
TrueConf Server is an on-premises videoconferencing platform used by a range of Russian government bodies and industrial enterprises as a domestic alternative to foreign conferencing software. Head Mare’s campaign targeted two vulnerabilities in the product, tracked by Kaspersky’s CERT as KLCERT-26-057 and KLCERT-26-058, affecting TrueConf Server versions 5.3.x prior to 5.3.9, 5.4.x prior to 5.4.9, 5.5.x prior to 5.5.5, and earlier releases. The vendor shipped patches on June 18, 2026, but Kaspersky’s telemetry shows active exploitation continuing into July, indicating a substantial population of unpatched servers remained exposed.
The attack chain proceeds in a tight, methodical sequence:
- Unauthenticated network access. Attackers connect directly to TCP port 4307, which TrueConf Server exposes by default, without needing valid credentials.
- Sandbox code execution (KLCERT-26-057). A malicious script is transmitted and executed inside TrueConf’s isolated processing environment.
- Sandbox escape (KLCERT-26-058). The second flaw is used to break out of that isolated environment and reach the underlying operating system directly.
- Privilege escalation to SYSTEM. The escape yields NT AUTHORITY\SYSTEM-level control of the host — the highest local privilege tier on Windows.
- Web shell persistence. The attackers overwrite the legitimate
public\js\locale.phpfile with a web shell, giving them a durable, low-visibility method of re-entering the server through what looks like a routine localisation script. - Installer substitution. With server-side control established, the attackers replace the legitimate TrueConf Client installers held on the server with trojanised, unsigned versions — meaning any employee or partner organisation subsequently downloading the “official” client from that server receives PhantomCore instead.
This is, in effect, a self-contained supply-chain attack: compromise one server, and every downstream user who trusts it as a software source becomes a potential secondary victim, without any additional phishing or social engineering required per victim.
Malware Arsenal: PhantomCore and PhantomGraph
Two distinct payload families feature in the campaign. PhantomCore is the backdoor delivered through the trojanised client installer — an unsigned executable distributed to organisation members who download what they believe is the legitimate TrueConf desktop client. Kaspersky’s detection signatures identify it as Backdoor.Win64.PhantomCore.dt, and it establishes persistence through a COM hijacking technique, planting itself under the registry key HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 so that it loads automatically whenever a legitimate process instantiates that CLSID.
PhantomGraph is a separate, two-component implant comprising SysExcSvc.dll and SysReadSvc.dll — one acting as a command receiver, the other as the executor — flagged under the detection name Trojan.Win64.PhantomGraph.gen. Its most notable feature is its command-and-control channel: rather than beaconing to attacker-registered infrastructure, PhantomGraph retrieves instructions through Microsoft OneDrive accounts. Using a mainstream, widely trusted cloud storage service as a dead-drop C2 mechanism lets malicious traffic blend into the large volume of legitimate Microsoft 365 and OneDrive activity that security teams routinely allowlist or under-scrutinise, complicating both network-based detection and any attempt to block the channel outright without disrupting business use of OneDrive.
Once deployed, PhantomGraph was observed conducting hands-on-keyboard activity consistent with active espionage or pre-ransomware reconnaissance: dumping LSASS process memory to harvest credentials, running basic system and user enumeration commands such as hostname and whoami queries, and establishing reverse SSH tunnels to enable lateral movement deeper into victim networks. Kaspersky’s separate research into the campaign’s infrastructure identified a cluster of supporting IP addresses — including 81.177.32[.]12, 194.87.239[.]71, 194.87.93[.]153, 38.244.205[.]244, and 31.59.102[.]61 — alongside a set of decoy-themed domains such as penzadogshelter[.]site, trendy-market[.]site, bright-deals[.]site, and nova-stream[.]site, registered to look unrelated to the campaign’s actual purpose.
Targeting and Victim Sectors
Kaspersky’s telemetry places the campaign’s victims exclusively within Russia, spanning instrumentation and electronics manufacturing, transportation, energy, IT, and software development organisations — sectors that broadly track Head Mare’s historical targeting pattern of government, transport, energy, and manufacturing entities. Initial access into individual victim networks, beyond the TrueConf-specific exploitation chain itself, has also involved phishing, exploitation of other public-facing web servers, and compromise via third-party contractors with network access into target organisations — a reminder that the TrueConf zero-day chain is one entry vector among several the group maintains in parallel, not a sole dependency.
It is worth noting the broader context: an unrelated April 2026 campaign, dubbed “Operation True Chaos” by Check Point Research and tentatively attributed to a Chinese-nexus actor, separately exploited a different TrueConf zero-day tracked as CVE-2026-3502. TrueConf’s position as a domestically preferred videoconferencing platform inside Russia appears to have made it a target of interest to multiple, unrelated threat actors with very different motivations across 2026 — both a pro-Ukraine hacktivist-turned-APT group and a suspected Chinese espionage operator found and exploited separate zero-days in the same product within a few months of each other.
Historical Context and Evolving Impact
Head Mare’s arc from a 2023 social-media hacktivist announcement to a 2026 APT designation illustrates a trajectory worth tracking across the broader pro-Ukraine hacktivist ecosystem, which includes groups like Twelve and BO Team operating with varying degrees of coordination against Russian and Belarusian targets. Early Head Mare operations relied entirely on a single disclosed, already-patched vulnerability (CVE-2023-38831 in WinRAR) and publicly leaked ransomware builders — a low-cost, low-sophistication approach typical of hacktivist groups drawing on freely available criminal tooling. Kaspersky’s own justification for the APT reclassification cites “sophisticated TTPs and absence of destructive activity,” suggesting the group’s newer campaigns favour quiet, persistent access over the immediate ransomware deployment and public shaming that characterised its earlier work — a shift from disruption-for-visibility toward sustained access, which is itself a marker of growing operational maturity and possibly a change in objectives toward longer-term intelligence collection rather than one-off reputational damage.
The TrueConf campaign is the clearest evidence yet of that maturation: finding two previously unknown vulnerabilities in a specific enterprise product, understanding its sandboxing architecture well enough to chain a script-execution bug into a full escape, and building a bespoke two-family malware set with a cloud-service C2 channel is a materially different capability profile from downloading a leaked LockBit builder. Whether this reflects Head Mare’s own organic skill growth, access to more capable operators joining its ranks, or support from a better-resourced third party remains unconfirmed in the public reporting, but the operational outcome — a working zero-day supply-chain compromise against critical infrastructure targets — is the same regardless of provenance.
Defensive Implications
Organisations running TrueConf Server should treat this campaign as confirmation that patching alone, after the fact, is not sufficient reassurance: the underlying flaws were exploited as zero-days for an unknown period before the June 18, 2026 patch, and Kaspersky’s telemetry shows continued exploitation of unpatched instances well into July. Practical steps for affected organisations and any enterprise running on-premises videoconferencing or collaboration platforms include:
- Patch immediately and verify. Confirm TrueConf Server instances are running 5.3.9, 5.4.9, 5.5.5, or later, and do not assume a prior patch cycle caught every instance — audit for shadow or forgotten deployments, particularly in industrial or OT-adjacent network segments where patching cadence often lags corporate IT.
- Restrict exposure of management and service ports. Port 4307 should not be reachable from untrusted or general user network segments; treat conferencing server administrative and service interfaces with the same network segmentation rigor applied to domain controllers or other Tier 0 assets.
- Treat locally distributed client installers with suspicion. Any organisation-hosted software distribution point — videoconferencing clients, internal tooling, VPN clients — is a viable trojanisation target once the hosting server is compromised. Code-signing verification on client installers, and monitoring for unsigned binaries distributed from previously trusted internal sources, would have caught the substituted TrueConf installers in this campaign.
- Hunt for COM hijacking persistence and unusual OneDrive API activity. Defenders should specifically check for unexpected entries under CLSID InprocServer32 registry paths and review OneDrive/Microsoft Graph API access logs for accounts exhibiting command-and-control-like polling patterns rather than genuine user file-sync behaviour, since this campaign demonstrates that trusted cloud services are an increasingly viable C2 channel that bypasses conventional domain and IP reputation blocking.
- Monitor LSASS access and reverse SSH tunnel indicators. Credential-dumping behaviour against LSASS and unexpected outbound SSH tunnel establishment are both detectable with standard EDR telemetry and should be treated as high-priority alerts on any host running conferencing or collaboration software.
- Reassess hacktivist groups in threat models. Security teams that categorise pro-Ukraine or other geopolitically-motivated hacktivist groups as lower-priority, noisy, ransomware-only threats should revisit that assumption. Head Mare’s trajectory shows that groups in this category can and do acquire zero-day discovery and supply-chain compromise capabilities associated with nation-state-grade operators, and threat models built on outdated capability assessments will under-prioritise genuinely dangerous campaigns.
The broader lesson for communications and critical infrastructure operators, inside or outside Russia, is that widely deployed enterprise collaboration software — videoconferencing platforms very much included — is now a first-tier target for both espionage-motivated APTs and geopolitically-driven hacktivist groups, and that the distinction between the two categories in terms of technical capability is narrowing.