Shared Infrastructure Blurs Hacktivist Boundaries in Russia Campaign
BO Team and Head Mare no longer look like separate hacktivist cells. Kaspersky found them using overlapping tools and command-and-control on the same compromised host, which means attribution based on actor names alone can miss a shared operational layer that survives disruption of either group.
The new report extends Kaspersky’s earlier view of BO Team as more autonomous. It also fits a broader shift in the group’s activity toward more covert operations, with both groups focused on Russian and Belarusian targets and BO Team active in attacks across manufacturing, telecom, and other sectors.
For defenders, the problem is persistence across identities. If one group’s infrastructure or access is reused by the other, blocking a single actor can leave the common host layer untouched and the campaign harder to map correctly.
Pro-Ukraine BO Team and Head Mare hackers appear to team up in attacks against Russia
Researchers at Moscow-based cybersecurity firm Kaspersky said they identified overlapping infrastructure and tools used by both groups — including command-and-control systems operating on the same compromised host — suggesting some coordination.