The Head Mare threat group has been exploiting unpatched TrueConf Server vulnerabilities to compromise conferencing servers and replace legitimate TrueConf client installers with trojanized packages that deploy the PhantomCore backdoor. According to reporting citing Kaspersky, the attackers chained two flaws tracked as KLCERT-26-057 and KLCERT-26-058 to gain unauthenticated access over TCP port 4307, break out of TrueConf’s isolated environment, escalate privileges to NT AUTHORITY\SYSTEM, and install a persistent web shell on the server.
The intrusion set also includes the PhantomGraph backdoor, which uses Microsoft OneDrive for command-and-control and has been observed conducting reconnaissance, dumping LSASS memory, and creating reverse SSH tunnels. Multiple active campaigns have reportedly targeted Russian organizations in instrumentation, electronics, transportation, energy, IT, and software development, while patched TrueConf Server releases addressing the issue were made available in versions 5.3.9, 5.4.9, and 5.5.5.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Kaspersky said it now assesses Head Mare as an APT group rather than hacktivists, citing the group's sophisticated tradecraft and the absence of destructive activity such as encryption or wiping. The reassessment accompanied Kaspersky's reporting on active campaigns targeting Russian organizations.
Kaspersky researchers discovered in July that Head Mare was exploiting unpatched TrueConf Server instances to gain unauthenticated access, escalate to NT AUTHORITY\SYSTEM, install a web shell, and replace legitimate client installers with trojanized PhantomCore versions. The activity was part of multiple active campaigns targeting Russian organizations.
TrueConf fixed the vulnerabilities later tracked by Kaspersky as KLCERT-26-057 and KLCERT-26-058 in TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5. The fixes covered affected 5.3.x, 5.4.x, 5.5.x, and older versions.
A threat research report revealed that Head Mare's trojanized TrueConf client installers delivered both PhantomCore and a second backdoor, PhantomGraph, which used Microsoft OneDrive for command-and-control and persisted as a Windows service. The report also published indicators of compromise including domains, IP addresses, MD5 hashes, and a registry path tied to the activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
16 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcemalware.news
Open sourcesecurelist.com
Open sourcescworld.com
Open sourcerescana.com
Open sourceopentip.kaspersky.com
Open sourceopentip.kaspersky.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.