HomeSecurityHacktivists Head Mare: Using WinRAR vulnerability for attacks on Russia

Hacktivists Head Mare: Using WinRAR vulnerability to attack Russia

A group of hacktivists, known as Head Mare, has been linked to attacks targeting Russia and Belarus, through the exploitation of a WinRAR vulnerability.

Head Mare Hacktivists

According to a Kaspersky report, attackers exploited the CVE-2023-38831 in WinRAR, which allows malicious code to be executed on the system via a specially crafted file.

“ This approach allows the team to deliver and disguise the malicious payload more effectively ,” the researchers say

Head Mare hacktivists are attacking Russian organizations in the context of the Russian-Ukrainian conflict that began in 2022.

See also: D-Link: Will not fix new vulnerabilities in DIR-846W router

The group is active in X, where it has leaked sensitive victim information. Targets of the attacks include the government, transportation, energy, construction, and environmental sectors.

As part of its attacks in Russia and Belarus, Head Mare also encrypts victims using LockBit ransomware (Windows) and Babuk (Linux, ESXi). Finally, it demands a ransom to decrypt data.

Hacktivists also use the PhantomDL backdoor that delivers additional payloads and uploads files to a command and control server, and PhantomCore (or PhantomRAT), a trojan that allows downloading files from the C2 server, uploading files from a compromised host to the C2 server, as well as executing commands in the cmd.exe command line interpreter.

“The attackers create scheduled tasks and registry values ​​named MicrosoftUpdateCore and MicrosoftUpdateCoree to disguise their activity as tasks related to Microsoft software,” Kaspersky said.

See also: Zyxel fixes critical vulnerability in routers

“We also found that some LockBit samples used by the group had the following names: OneDrive.exe [and] VLC.exe. These samples were located in the C:\ProgramData directory, disguised as legitimate OneDrive and VLC applications.” The researchers observed that these were distributed via phishing.

WinRAR vulnerability attacks Russia
Hacktivists Head Mare: Using WinRAR vulnerability to attack Russia

Another useful tool for hacktivists is Sliver, an open-source C2 framework.

The attacks culminate in the deployment of either LockBit or Babuk depending on the target environment.

“The tactics, methods, procedures and tools used by the Head Mare group are generally similar to those of other groups targeting organizations in Russia and Belarus in the context of the Russian-Ukrainian conflict,” Kaspersky said.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“However, the group stands out due to its use of custom software, such as PhantomDL and PhantomCore, as well as its exploitation of a relatively new vulnerability (in WinRAR)“.

See also: Canonical releases updates for AWS vulnerabilities

Head Mare’s activities demonstrate not only its technical capabilities but also its determination to cause harm and disrupt businesses in Russia and Belarus. Therefore, it is imperative for all organizations to be vigilant against potential cyber attacks and take proactive measures to protect themselves from malicious actors. Cybersecurity is an ever-evolving landscape, requiring constant adaptation and collaboration for businesses to stay ahead of cyber threats.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS