Recent findings from Kaspersky reveal that two threat actors, Head Mare and Twelve, have likely joined forces to target Russian organizations. Evidence shows Head Mare using tools previously associated with Twelve and utilizing command-and-control servers exclusively linked to Twelve, suggesting collaboration between these groups.
## Attack Methods and Tools
Head Mare, first documented in September 2024, exploits various vulnerabilities for initial access, including:
– WinRAR vulnerability (CVE-2023-38831)
– Microsoft Exchange Server flaws (ProxyLogon)
– Phishing emails with malicious attachments
– Compromising contractor networks (trusted relationship attacks)
The group has expanded its toolkit to include:
– CobInt backdoor (previously used by ExCobalt and Crypt Ghouls)
– PhantomJitter implant for remote command execution
– Various reconnaissance tools including fscan and ADRecon
– Credential harvesting tools like Mimikatz
## Attack Progression
After gaining access, the attackers:
1. Create privileged local user accounts on business automation servers
2. Connect via RDP to transfer and execute tools
3. Disguise malicious payloads as legitimate system files
4. Remove evidence by clearing event logs
5. Use proxy tools like Gost and Cloudflared to hide network traffic
6. Deploy LockBit 3.0 and Babuk ransomware
7. Leave ransom notes directing victims to Telegram
Twelve, meanwhile, has been known for destructive attacks that encrypt data and deploy wipers to prevent recovery.
The collaboration between these groups, along with connections to other actors like Crypt Ghouls, indicates a complex network of threat actors currently targeting Russian state and private companies.
