Head Mare is a pro-Ukraine intrusion set that has evolved from being described as a hacktivist group into an APT-class actor based on sustained operations, custom malware development, and increasingly sophisticated tradecraft. The group is also tracked as Rainbow Hyena. Its activity has focused primarily on Russian organizations, with some reporting also placing Belarus in scope. Known targeting includes government and public-sector entities as well as organizations in aerospace, defense-adjacent manufacturing, electronics, instrumentation, transportation, energy, information technology, software development, logistics, finance, and other industrial sectors. Head Mare has used multiple initial access vectors, including spearphishing, exploitation of public-facing applications, abuse of trusted relationships and contractors, and use of compromised mail infrastructure to distribute malicious lures. In 2024 and 2025 reporting, the group was linked to phishing campaigns delivering custom malware and to exploitation of vulnerabilities in products such as WinRAR, Microsoft Exchange, and especially TrueConf Server. By 2026, Head Mare was repeatedly observed exploiting TrueConf Server vulnerabilities to obtain unauthenticated code execution and SYSTEM-level access, deploy a web shell, access the TrueConf database, and replace legitimate client installers with trojanized versions. This created a supply-chain-style infection path in which downstream users connecting to compromised servers could receive malicious software. The group’s malware arsenal includes PhantomCore, PhantomGraph, PhantomHeart, PhantomRemote, PhantomJitter, PhantomProxyLite, PhantomRAT, and CobInt. PhantomCore has been used as a backdoor for remote command execution, reconnaissance, persistence, and credential access, including LSASS memory dumping. PhantomGraph has been deployed as a modular backdoor installed as Windows services and has used Microsoft OneDrive as a command-and-control channel. PhantomHeart and PhantomProxyLite reflect a stronger living-off-the-land approach centered on native PowerShell and OpenSSH components, including reverse SSH tunneling for covert access and pivoting. Earlier reporting also tied Head Mare to PhantomRemote delivery through phishing and to PhantomJitter in intrusions overlapping with the group Twelve. Observed post-compromise behavior includes reconnaissance, credential theft, persistence through Windows services, scheduled tasks, COM hijacking, and creation of privileged local accounts; use of reverse SSH tunnels and proxy tooling for lateral movement and remote access; selective data exfiltration; and extensive defense evasion through masquerading, service removal, and event log clearing. In some 2024 intrusions, researchers assessed that Head Mare likely cooperated with Twelve, citing shared tooling, infrastructure, and overlapping victimology. Those operations also culminated in deployment of LockBit 3.0 on Windows systems and Babuk on NAS devices, indicating that at least some Head Mare-linked campaigns combined espionage, disruption, and extortionary or destructive effects. Although public reporting has at times labeled Head Mare as hacktivist, the dominant pattern is a politically aligned, pro-Ukraine actor conducting sustained intrusions against Russian interests with custom malware, credential theft, tunneling, exploitation of exposed services, and occasional ransomware-associated impact. Attribution to Ukraine is supported in multiple reports, but the precise degree of state direction is not publicly established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
In one incident, they exploited the Microsoft Exchange server vulnerability CVE-2021-26855 (ProxyLogon). Although patched in 2021, this vulnerability is still exploitable due to organizations using outdated operating systems and software. The attackers used ProxyLogon to execute a command to download and launch CobInt on the server.
The attackers also exploited software vulnerabilities, most commonly CVE-2023-38831 in WinRAR through phishing emails.
169 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploiting unpatched TrueConf servers to gain SYSTEM-level execution, deploy a web shell, collect infrastructure data, access the TrueConf database, and replace legitimate TrueConf Client installers with trojanized versions containing the PhantomCore backdoor, potentially compromising conference participants.
Conducting multi-stage intrusions via TrueConf Server vulnerabilities, deploying web shells, replacing legitimate TrueConf client installers with trojanized versions, and installing PhantomCore and PhantomGraph backdoors for persistence, reconnaissance, credential access, and remote control.
Conducting APT-style intrusions against Russian organizations by exploiting TrueConf Server vulnerabilities, deploying web shells, replacing legitimate TrueConf client installers with trojanized versions, and installing PhantomCore and PhantomGraph backdoors for persistence, reconnaissance, credential access, and remote control.
Exploiting unpatched TrueConf server vulnerabilities to trojanize client installers and deliver backdoors, while targeting Russian organizations across multiple sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.