PULSE NAME
Head Mare campaign with PhantomPxPigeon backdoor and infected TrueConf software installation files
WHITE Head Mare PetrP.73 2026-03-23 Modified: 2026-03-23
20
IOCs
MEDIUM VOLUME
In February 2026, a campaign attributed to the Head Mare group began targeting educational and scientific institutions, alongside organizations in the energy sector across Russia. This malicious activity was active since at least December 2025, utilizing an attack vector that involved deceptive video conference invitations. Victims who clicked on the invitation links were instructed to install a service to join the video call, which inadvertently led to the installation of a new backdoor identified as PhantomPxPigeon on their systems.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (20)
All FileHash-MD5 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1561054283df80dade88b6366f6a94b2 2026-03-23
FileHash-MD5 1eab157b9a32c75fbac1dbb6475d51b5 2026-03-23
FileHash-MD5 2e0be66779b6fbd103f525e6e773a3b8 2026-03-23
FileHash-MD5 3244e1ba4c477da4d56267efc6ae77eb 2026-03-23
FileHash-MD5 3af8b18ca909072dd08b8603105593fe 2026-03-23
FileHash-MD5 419e57227affbed899e7e8388995b956 2026-03-23
FileHash-MD5 51b2e4bb58e7d31101cbb389fda5ea34 2026-03-23
FileHash-MD5 577713df800f6ac690cb2189a4b036e9 2026-03-23
FileHash-MD5 5c82f1363fd8805875eb2a9c3d0a5dec 2026-03-23
FileHash-MD5 6ff6b3b56602451486ec46aaf3baf50f 2026-03-23
FileHash-MD5 83d4552f5b03cbad798ddb5ecef73d75 2026-03-23
FileHash-MD5 8a1e4537ff319920602a2642083eb2ab 2026-03-23
FileHash-MD5 a8d26d296100342d0c9e0b688c607d73 2026-03-23
FileHash-MD5 a92a9b9258091aa47e770d4dea7a19a3 2026-03-23
FileHash-MD5 aa9722e369ea0be406494101e5d240de 2026-03-23
FileHash-MD5 b83c970bb871b56ed6746c757700d92e 2026-03-23
FileHash-MD5 bcf39d3ed3110fa2b1c13bb1192a4d31 2026-03-23
FileHash-MD5 ea5f0bab47e33e63d8894ea4154491d2 2026-03-23
domain ironshieldsecurity.space 2026-03-23
domain primeinfosec.space 2026-03-23