Threats & Adversaries

Shared Infrastructure Blurs Hacktivist Boundaries in Russia Campaign

BO Team and Head Mare no longer look like separate hacktivist cells. Kaspersky found them using overlapping tools and command-and-control on the same compromised host, which means attribution based on actor names alone can miss a shared operational layer that survives disruption of either group.

The new report extends Kaspersky’s earlier view of BO Team as more autonomous. It also fits a broader shift in the group’s activity toward more covert operations, with both groups focused on Russian and Belarusian targets and BO Team active in attacks across manufacturing, telecom, and other sectors.

For defenders, the problem is persistence across identities. If one group’s infrastructure or access is reused by the other, blocking a single actor can leave the common host layer untouched and the campaign harder to map correctly.

1 source · May 8

Timeline

Sources

Part of the PlainSec briefing for 2026-05-08

Every edition of this story: Shared Infrastructure Blurs Hacktivist Boundaries in Russia Campaign

More from today