Head Mare is a hacktivist group that first made itself known in 2023 on the social network X (formerly Twitter). In their public posts, the attackers reveal information about some of their victims, including organization names, internal documents stolen during attacks, and screenshots of desktops and administrative consoles.
By analyzing incidents in Russian companies, Kaspersky researchers identified how Head Mare conducts its attacks, the tools it uses, and established the group’s connection with the PhantomDL malware.
Read more…
Source: Kaspersky
Related:
- Hackers steal over $130M by exploiting bug in offline hardware wallets
August 4, 2026
Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists. At least a dozen different hackers are said to be targeting Bitcoin owners who use the hardware crypto wallet Coldcard, made by Coinkite. At this point, it’s unclear who is behind ...
- Feds get 3 days to patch N-able God mode flaw under active exploit
August 4, 2026
The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies three days to patch a flaw that could let attackers reach managed service provider (MSP) customers. Attackers exploiting the flaw can gain “full administrative access to an N-central console,” Tracked as CVE-2026-18577 (8.2 ...
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
August 3, 2026
This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. Palo Alto Unit 42 shows how an attacker can authenticate ...
- INTERPOL report finds AI linked to more than half of cybercrime in Africa
August 3, 2026
Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026. With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly. However, cybercrime legislation is fragmented and AI readiness ...
- Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
July 31, 2026
Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, ...
- Network Anomaly Detection in KATA
July 31, 2026
Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. Because this activity is virtually indistinguishable from legitimate network traffic, it is extremely difficult to detect it with traditional ...

