← All stories
● Covered by 3 sources · 4 reportsMedium impact4 negative

Head Mare Exploits TrueConf Server Flaws to Distribute Backdoored Client Installers

🔄 Updated 42d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Head Mare exploited TrueConf server vulnerabilities.
  • Malicious installers delivered PhantomCore and PhantomGraph backdoors.
  • Attacks targeted Russian enterprise and government sectors.
  • Vulnerabilities KLCERT-26-057 and KLCERT-26-058 were used.
  • Impacted TrueConf server versions 5.3.x, 5.4.x, and 5.5.x.
  • CISA warned federal agencies about the vulnerabilities.
  • Vulnerabilities are tracked as CVE-2026-72529 and CVE-2026-72530.
  • CVE-2026-72529 allows calling an undocumented function and executing scripts.
  • CVE-2026-72530 enables escaping isolated environment and executing scripts.
  • Vulnerabilities can be exploited via port 4307/TCP.
  • Vulnerabilities were addressed in June 2026.
  • TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 fixed the vulnerabilities.
  • CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog.
  • Federal agencies must patch CVE-2026-72529 within three days.
  • Federal agencies must patch CVE-2026-72530 within two weeks.
  • Federal agencies must patch CVE-2026-72529 and CVE-2026-72530 by September 3.

Overview of the Attack

The hacktivist group Head Mare has been exploiting security flaws in unpatched TrueConf video conferencing servers. The attackers replaced legitimate client installers with malicious versions that deliver the PhantomCore and PhantomGraph backdoors.

These backdoored installers allow attackers to gain persistent remote access, exfiltrate credentials, and conduct reconnaissance on compromised systems. The attacks were detected by cybersecurity company Kaspersky in July.

Targeted Organizations and TrueConf's Role

The attacks primarily targeted Russian companies across multiple sectors, including instrumentation, electronics, transport, energy, IT, and software development. TrueConf is widely used in Russia, particularly in enterprise and government sectors, as an on-premise alternative to Western video conferencing tools.

The affected TrueConf server versions include 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier versions.

Exploited Vulnerabilities and Attack Chain

Head Mare leveraged a chain of vulnerabilities, internally tracked by Kaspersky as KLCERT-26-057 and KLCERT-26-058. These flaws enable arbitrary code execution with elevated privileges.

The attack chain begins with attackers connecting to the TrueConf server on TCP port 4307, which is open by default. They then exploit KLCERT-26-057 to run a malicious script within TrueConf's isolated environment. KLCERT-26-058 is used to escape this sandbox and execute commands on the underlying operating system. Attackers then escalate privileges to NT AUTHORITY\SYSTEM and replace the ‘\public\js\locale.php’ file with a web shell for persistent remote access.

Impact of the Backdoors

The PhantomCore and PhantomGraph backdoors provide attackers with capabilities such as persistent remote access and the ability to collect infrastructure data. This allows for ongoing surveillance and data exfiltration from compromised networks.

Updates

🕒 2026-08-21 · new reporting from BleepingComputer
  • Federal agencies must patch CVE-2026-72529 and CVE-2026-72530 by September 3.
🕒 2026-08-21 · new reporting from SecurityWeek
  • CISA warned federal agencies about the vulnerabilities.
  • Vulnerabilities are tracked as CVE-2026-72529 and CVE-2026-72530.
  • CVE-2026-72529 allows calling an undocumented function and executing scripts.
  • CVE-2026-72530 enables escaping isolated environment and executing scripts.
  • Vulnerabilities can be exploited via port 4307/TCP.
  • Vulnerabilities were addressed in June 2026.
  • TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 fixed the vulnerabilities.
  • CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog.
  • Federal agencies must patch CVE-2026-72529 within three days.
  • Federal agencies must patch CVE-2026-72530 within two weeks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

CISA has directed U.S. federal agencies to patch two actively exploited critical vulnerabilities, CVE-2026-72529 and CVE-2026-72530, in the TrueConf Server communications platform by September 3. These flaws allow remote code execution and have been exploited by the Head Mare hacktivist group to deploy backdoor malware. The directive highlights the ongoing threat to organizations using self-hosted communication solutions.

CISA has warned federal agencies about two critical vulnerabilities in TrueConf Server (CVE-2026-72529 and CVE-2026-72530) that are actively being exploited by the hacktivist group Head Mare. These flaws allow remote code execution and have been used to deploy PhantomCore malware and backdoors, necessitating immediate patching for affected organizations.

The threat actor Head Mare exploited vulnerabilities in unpatched TrueConf videoconferencing servers to replace legitimate client installers with malicious versions containing the PhantomCore backdoor and RAT. This attack targeted Russian companies across multiple sectors, allowing attackers to gain privileged access, collect infrastructure data, and establish persistent presence.

The Head Mare hacktivist group is exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing PhantomCore and PhantomGraph backdoors. This allows attackers to gain persistent remote access, exfiltrate credentials, and conduct reconnaissance, impacting organizations using TrueConf, particularly in Russia's enterprise and government sectors.