Analysis critical-infrastructurecommunications
Head Mare Graduates to APT: Zero-Day TrueConf Exploitation Delivers PhantomCore and PhantomGraph via OneDrive C2
Kaspersky has upgraded pro-Ukraine hacktivist group Head Mare to APT status after documenting a July 2026 campaign that chained two unpatched TrueConf videoconferencing flaws into SYSTEM-level compromise, trojanised client installers, and a Microsoft OneDrive-based command channel against Russian critical infrastructure.