The hacktivist group Head Mare has been exploiting security flaws in unpatched TrueConf video conferencing servers. The attackers replaced legitimate client installers with malicious versions that deliver the PhantomCore and PhantomGraph backdoors.
These backdoored installers allow attackers to gain persistent remote access, exfiltrate credentials, and conduct reconnaissance on compromised systems. The attacks were detected by cybersecurity company Kaspersky in July.
The attacks primarily targeted Russian companies across multiple sectors, including instrumentation, electronics, transport, energy, IT, and software development. TrueConf is widely used in Russia, particularly in enterprise and government sectors, as an on-premise alternative to Western video conferencing tools.
The affected TrueConf server versions include 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier versions.
Head Mare leveraged a chain of vulnerabilities, internally tracked by Kaspersky as KLCERT-26-057 and KLCERT-26-058. These flaws enable arbitrary code execution with elevated privileges.
The attack chain begins with attackers connecting to the TrueConf server on TCP port 4307, which is open by default. They then exploit KLCERT-26-057 to run a malicious script within TrueConf's isolated environment. KLCERT-26-058 is used to escape this sandbox and execute commands on the underlying operating system. Attackers then escalate privileges to NT AUTHORITY\SYSTEM and replace the ‘\public\js\locale.php’ file with a web shell for persistent remote access.
The PhantomCore and PhantomGraph backdoors provide attackers with capabilities such as persistent remote access and the ability to collect infrastructure data. This allows for ongoing surveillance and data exfiltration from compromised networks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The threat actor Head Mare exploited vulnerabilities in unpatched TrueConf videoconferencing servers to replace legitimate client installers with malicious versions containing the PhantomCore backdoor and RAT. This attack targeted Russian companies across multiple sectors, allowing attackers to gain privileged access, collect infrastructure data, and establish persistent presence.
The Head Mare hacktivist group is exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing PhantomCore and PhantomGraph backdoors. This allows attackers to gain persistent remote access, exfiltrate credentials, and conduct reconnaissance, impacting organizations using TrueConf, particularly in Russia's enterprise and government sectors.