Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
exploitHackVulnerability

Head Mare Hacktivists Trojanize TrueConf Installers to Deploy PhantomCore and PhantomGraph Backdoors

By ogwatermelon
August 10, 2026 4 Min Read
0
August 10, 2026

The Head Mare hacktivist group has been exploiting unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions that deliver backdoors. Researchers at Kaspersky discovered the campaign in July 2026. It is now targeting Russian organizations across multiple sectors including energy, transportation, and software development.

What Happened: Head Mare Hacktivists Trojanize TrueConf Installers

Head Mare is a hacktivist group known for targeting Russian entities. In this campaign, the group exploited two vulnerabilities in TrueConf Server to gain full control over the underlying operating system. TrueConf is a popular on-premise video conferencing platform in Russia. It is widely used by government and enterprise customers as a domestic alternative to Zoom and Microsoft Teams.

The attackers used TCP port 4307, which is open by default, to connect to target servers without authentication. They then leveraged two flaws tracked as KLCERT-26-057 and KLCERT-26-058. The first flaw allowed them to execute a malicious script inside TrueConf’s isolated environment. The second flaw allowed them to escape the sandbox and run commands directly on the host operating system.

After escalating privileges to NT AUTHORITY\SYSTEM, the attackers replaced a PHP file on the server with a web shell. This gave them persistent remote access. They then used the web shell to replace the legitimate TrueConf Client installer with a malicious version containing the PhantomCore backdoor. When employees connected to the compromised server, they received the trojanized installer as an update.

Technical Details of the TrueConf Backdoor Attack

The attack deploys two distinct backdoors: PhantomCore and PhantomGraph. PhantomCore is embedded inside the trojanized TrueConf Client installer. It is delivered to users when they download the client from a compromised server. PhantomGraph is a separate backdoor that uses two DLL files to accept commands through a Microsoft OneDrive account.

PhantomGraph’s command-and-control mechanism is notable. The backdoor connects to a Microsoft OneDrive account to retrieve commands. It then executes those commands and returns the results to the same OneDrive account. This technique blends attacker traffic with legitimate cloud service activity. Consequently, it can evade network-level detection that focuses on suspicious domains or IPs.

Observed attacker activity through PhantomGraph included:

  • Dumping the memory of the LSASS process to steal credentials
  • Running reconnaissance commands such as hostname and whoami
  • Starting reverse SSH tunnels for persistent remote access

Kaspersky also warned that the risk extends beyond direct users. Employees of organizations that do not use TrueConf themselves may still connect to compromised counterparty servers for meetings. In those cases, they can also download infected installation packages.

Business and Operational Impact

The Head Mare campaign has broad implications for organizations using TrueConf, especially in Russia and neighboring regions. The trojanized installer mechanism turns a trusted software update channel into a malware delivery pipeline. Therefore, even security-conscious users who verify server identity can be compromised if the server itself is under attacker control.

Key impact areas include:

  • Credential theft: LSASS memory dumps expose domain and local account credentials
  • Lateral movement: Reverse SSH tunnels enable attackers to pivot across the network
  • Supply-chain risk: Business partners connecting to compromised servers can also be infected
  • Reputational damage: Organizations hosting compromised installers may unknowingly distribute malware to clients

Kaspersky reports active campaigns in instrumentation, electronics, transportation, energy, IT, and software development sectors. The group uses multiple initial access methods including phishing, exploiting public-facing web servers, and access via contractors.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Upgrade TrueConf Server to version 5.3.9, 5.4.9, or 5.5.5 or later immediately
  2. Restrict TCP port 4307 to authorized management hosts only
  3. Review server file integrity, especially \public\js\locale.php, for unauthorized modifications
  4. Audit all TrueConf Client installers on internal update servers for valid digital signatures
  5. Block or monitor Microsoft OneDrive traffic from server subnets if not required for business

Detection and Monitoring Guidance

Security teams should monitor for signs of compromise on TrueConf servers. Indicators include unexpected file changes in the web root, outbound connections to OneDrive from non-user systems, and LSASS memory access by non-standard processes. Network segmentation can limit the blast radius if a server is compromised.

Bottom line: This attack turns a trusted software update mechanism into a malware delivery channel. Patching alone is not enough. Organizations must also verify installer integrity, restrict server exposure, and monitor for abnormal cloud service usage from server infrastructure.

Incident Summary

Incident: Head Mare TrueConf Server Compromise and Trojanized Installer Campaign
Affected Systems: TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5
Threat Actor: Head Mare hacktivist group
Backdoors Deployed: PhantomCore (trojanized installer), PhantomGraph (OneDrive C2 DLLs)
Disclosure Date: August 8, 2026 (Kaspersky publication)
Patch Status: Patches available since June 18, 2026
Attack Vector: Unauthenticated TCP port 4307 access, sandbox escape, privilege escalation

References

  1. Kaspersky Securelist, “Head Mare Targets TrueConf Server with PhantomCore,” August 2026, https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/, accessed August 10, 2026.
  2. BleepingComputer, “Hackers breach TrueConf to trojanize client installers with backdoors,” August 8, 2026, https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/, accessed August 10, 2026.
  3. Check Point Research, “Operation True Chaos: Hackers Exploit TrueConf Zero-Day,” April 2026, https://www.bleepingcomputer.com/news/security/hackers-exploit-trueconf-zero-day-to-push-malicious-software-updates/, accessed August 10, 2026.

Tags:

ExploitHackVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

SCTPhantom Linux Kernel Flaw: 18-Year-Old SCTP Bug Enables Root and Container Escape

Next

Solidity Pro VS Code Extensions Steal Crypto Wallets and Developer Credentials

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.