PhantomCore is a Windows DLL-based backdoor associated with the Head Mare threat actor. It was distributed through trojanized TrueConf Client installers placed on compromised on-premises TrueConf Server instances, while preserving installation of the legitimate conferencing client. Users downloading or updating the client from an affected server, including meeting participants from third-party organizations, could receive the backdoor. PhantomCore provides remote arbitrary command execution and system control, conducts host reconnaissance, communicates with command-and-control infrastructure, and steals credentials through LSASS memory dumping. It establishes persistence through COM hijacking. Head Mare used PhantomCore in campaigns targeting Russian organizations in instrumentation, electronics, transportation, energy, IT, and software-development sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
With an initial foothold on the server, attackers then chained the second vulnerability, CVE-2026-72530, which enabled them to escape the isolated environment and execute arbitrary code on the server with system privileges. | The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.”
Kaspersky discovered that Head Mare attackers were using CVE-2026-72529 to gain initial access to TrueConf servers; the vulnerability enables remote, unauthorized access over the network via port 4307/TCP and execution of arbitrary scripts within an isolated environment by calling an undocumented function. | The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Head Mare replaces the legitimate TrueConf Client installer on compromised servers with a malicious version containing the PhantomCore backdoor, delivered to users as an update.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
An unauthorized attacker can connect to TrueConf server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5 ... via port 4307/TCP ... and execute a malicious script on the server by calling an undocumented function.
The attackers also replaced the TrueConf client distribution file, trueconf_windows_client_x64.exe, with a malicious version causing users who joined a TrueConf meeting on a compromised server to receive a prompt to install the trojanized version.
[They] replace the legitimate TrueConf Client installer on the server with a malicious version containing the PhantomCore backdoor. When members of an organization connect to a compromised local TrueConf server, they can receive the trojanized installer as an update.
all subsequent actions are carried out by remotely running PowerShell scripts via a web shell.
The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.”
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
To automatically launch the malware after system startup, a registry key is created: HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32
This enables them to replace the file C:/Program Files/TrueConf Server/httpconf/site/public/js/locale.php with a malicious web shell program... Attackers use the web shell to install a backdoor-type malicious program on the server
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
Head Mare leveraged this access to replace a TrueConf file, locale.php, with a web shell and install a backdoor, enabling further command execution
The second vulnerability let attackers break out of an isolated execution environment and run code with NT AUTHORITY\SYSTEM privileges, granting full control of the server.
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
Head Mare leveraged this access to replace a TrueConf file, locale.php, with a web shell and install a backdoor, enabling further command execution
as well as delete records from the TrueConf event logs related to the exploit’s operation.
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
90 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor embedded in trojanized TrueConf Client installers and distributed through compromised on-premise TrueConf servers.
A malware payload delivered via a trojanized TrueConf client installer that gives attackers arbitrary command execution and effectively full control over infected systems.
A backdoor delivered via a trojanized TrueConf Windows client installer after attackers compromised TrueConf servers, creating a supply-chain-style risk for meeting participants downloading the client from hacked infrastructure.
Malware deployed via trojanized TrueConf client installers after exploitation of TrueConf server vulnerabilities. It is associated with Head Mare intrusions and the campaign context indicates destructive activity, including file-encrypting behavior and ransom demands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.