The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to switch shopper installers with malicious variations that ship backdoors.
The exploited vulnerabilities allowed the attacker to execute arbitrary code with the very best degree of privileges and deploy the PhantomCore and PhantomGraph backdoors.
TrueConf is a video conferencing software extensively utilized in Russia, particularly within the enterprise and authorities sectors, as a safe, on-premise various to Western instruments akin to Zoom and Microsoft Groups.
Researchers at cybersecurity firm Kaspersky found the assault in July. They discovered that Head Mare hackers used TCP port 4307, which is open by default, to hook up with the goal TrueConf server with out authentication.
They leveraged a vulnerability internally tracked by Kaspersky as KLCERT-26-057 to execute a malicious script inside TrueConf’s remoted atmosphere, and KLCERT-26-058 to flee the sandbox and run instructions on the underlying working system.
The attacker then elevated their privileges to NT AUTHORITYSYSTEM, and changed the ‘publicjslocale.php’ file with an online shell that gave them persistent distant entry to the compromised server.
Kaspersky stories that Head Mare makes use of an online shell to gather delicate data from the sufferer’s atmosphere, entry the TrueConf database, and substitute the professional TrueConf Shopper installer hosted on the server with a malicious model that accommodates the PhantomCore backdoor.
When members of the group hook up with the native TrueConf server, they obtain a trojanized, non-digitally signed shopper installer as an replace.
“Even when your group doesn’t use the TrueConf server, workers of the group can hook up with compromised counterparty TrueConf servers to take part in on-line conferences and obtain contaminated set up packages,” Kaspersky warns.
Moreover, Head Mare deploys PhantomGraph, a separate backdoor consisting of two DLL information (SysExcSvc.dll and SysReadSvc.dll) that settle for instructions through a Microsoft OneDrive account, execute them, and return the outcomes.
Noticed attacker exercise via PhantomGraph included dumping the reminiscence of the Native Safety Authority Subsystem Service (LSASS) course of to exfiltrate credentials.
The malware additionally runs instructions for reconnaissance exercise, akin to hostname and whoami, and begins a reverse SSH tunnel.
Kaspersky says it’s presently observing a number of lively Head Mare campaigns concentrating on Russian organizations in numerous sectors: instrumentation, electronics, transportation, power, IT, and software program growth.
In response to the researchers, the risk actor is utilizing a number of preliminary entry strategies that embody phishing, exploiting public-facing net servers, and entry through contractors.
TrueConf vulnerabilities
The 2 flaws Kaspersky noticed leveraged in assaults have an effect on TrueConf Server 5.3.x earlier than 5.3.9, 5.4.x earlier than 5.4.9, 5.5.x earlier than 5.5.5, and older variations.
The seller mounted them in variations 5.3.9, 5.4.9, and 5.5.5, launched on June 18.
In April 2026, CheckPoint Analysis reported that hackers have been concentrating on a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502, compromising customers through trojanized shopper updates.
CheckPoint named the marketing campaign ‘Operation True Chaos,’ and tentatively attributed it to Chinese language risk actors behind the Havoc implant, which was utilized in these assaults.
Safety groups log 54% of profitable assaults and alert on simply 14%. The remainder transfer via your atmosphere unseen.
The Picus whitepaper exhibits how breach and assault simulation assessments your SIEM and EDR guidelines so threats cease slipping by detection.


