← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Head Mare Exploits TrueConf Server Flaws to Distribute Backdoored Client Installers

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Head Mare exploited TrueConf server vulnerabilities.
  • Malicious installers delivered PhantomCore and PhantomGraph backdoors.
  • Attacks targeted Russian enterprise and government sectors.
  • Vulnerabilities KLCERT-26-057 and KLCERT-26-058 were used.
  • Impacted TrueConf server versions 5.3.x, 5.4.x, and 5.5.x.

Overview of the Attack

The hacktivist group Head Mare has been exploiting security flaws in unpatched TrueConf video conferencing servers. The attackers replaced legitimate client installers with malicious versions that deliver the PhantomCore and PhantomGraph backdoors.

These backdoored installers allow attackers to gain persistent remote access, exfiltrate credentials, and conduct reconnaissance on compromised systems. The attacks were detected by cybersecurity company Kaspersky in July.

Targeted Organizations and TrueConf's Role

The attacks primarily targeted Russian companies across multiple sectors, including instrumentation, electronics, transport, energy, IT, and software development. TrueConf is widely used in Russia, particularly in enterprise and government sectors, as an on-premise alternative to Western video conferencing tools.

The affected TrueConf server versions include 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier versions.

Exploited Vulnerabilities and Attack Chain

Head Mare leveraged a chain of vulnerabilities, internally tracked by Kaspersky as KLCERT-26-057 and KLCERT-26-058. These flaws enable arbitrary code execution with elevated privileges.

The attack chain begins with attackers connecting to the TrueConf server on TCP port 4307, which is open by default. They then exploit KLCERT-26-057 to run a malicious script within TrueConf's isolated environment. KLCERT-26-058 is used to escape this sandbox and execute commands on the underlying operating system. Attackers then escalate privileges to NT AUTHORITY\SYSTEM and replace the ‘\public\js\locale.php’ file with a web shell for persistent remote access.

Impact of the Backdoors

The PhantomCore and PhantomGraph backdoors provide attackers with capabilities such as persistent remote access and the ability to collect infrastructure data. This allows for ongoing surveillance and data exfiltration from compromised networks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The threat actor Head Mare exploited vulnerabilities in unpatched TrueConf videoconferencing servers to replace legitimate client installers with malicious versions containing the PhantomCore backdoor and RAT. This attack targeted Russian companies across multiple sectors, allowing attackers to gain privileged access, collect infrastructure data, and establish persistent presence.

The Head Mare hacktivist group is exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing PhantomCore and PhantomGraph backdoors. This allows attackers to gain persistent remote access, exfiltrate credentials, and conduct reconnaissance, impacting organizations using TrueConf, particularly in Russia's enterprise and government sectors.