A hacktivist group known as Head Mare has been linked to a series of cyber attacks that exclusively target organizations in Russia and Belarus.
In a recent analysis, cybersecurity firm Kaspersky shed light on the group’s tactics and tools, noting, "Head Mare uses more up-to-date methods for obtaining initial access." One notable method is exploiting the relatively new CVE-2023-38831 vulnerability in WinRAR. This vulnerability allows attackers to execute arbitrary code on a system via a specially crafted archive, enabling them to deliver and disguise malicious payloads more effectively.
Active since 2023, Head Mare is one of several hacktivist groups involved in the ongoing Russo-Ukrainian conflict, which began the previous year. The group maintains a presence on social media platform X, where it has leaked sensitive information and internal documentation from its victims. The group's targets span various sectors, including government, transportation, energy, manufacturing, and the environment.
Unlike other hacktivist entities that focus on causing maximum damage, Head Mare goes a step further by encrypting victims' devices using ransomware like LockBit for Windows and Babuk for Linux (ESXi). The group then demands a ransom for decrypting the data.
Part of the group's toolkit includes PhantomDL and PhantomCore. PhantomDL is a Go-based backdoor that can deliver additional payloads and upload files of interest to a command-and-control (C2) server. PhantomCore, also known as PhantomRAT, is a predecessor to PhantomDL and functions as a remote access trojan. It allows the group to download files from the C2 server, upload files from compromised hosts, and execute commands via the cmd.exe command line interpreter.
Kaspersky's report highlights that the attackers create scheduled tasks and registry values named "MicrosoftUpdateCore" and "MicrosoftUpdateCoree" to disguise their activities as legitimate Microsoft software tasks. They also found that some LockBit samples used by the group were named "OneDrive.exe" and "VLC.exe," and were located in the C:\ProgramData directory to masquerade as legitimate applications.
These malicious artifacts have been distributed through phishing campaigns that deliver business documents with double extensions, such as "решение №201-5_10вэ_001-24 к пив экран-сои-2.pdf.exe" or "тз на разработку.pdf.exe."
Another key component of the group's attack strategy is the use of Sliver, an open-source C2 framework. The group also leverages various publicly available tools, such as rsockstun, ngrok, and Mimikatz, which facilitate discovery, lateral movement, and credential harvesting.
The attacks typically culminate in the deployment of either LockBit or Babuk ransomware, depending on the target environment. Once the ransomware is deployed, a ransom note is dropped, demanding payment in exchange for a decryptor to unlock the files.
"The tactics, methods, procedures, and tools used by the Head Mare group are generally similar to those of other groups associated with clusters targeting organizations in Russia and Belarus within the context of the Russo-Ukrainian conflict," Kaspersky noted. "However, the group distinguishes itself by using custom-made malware such as PhantomDL and PhantomCore, as well as exploiting a relatively new vulnerability, CVE-2023-38831, to infiltrate the infrastructure of their victims in phishing campaigns."