Head Mare Hackers Trojanize TrueConf Updates via Critical Server Vulnerabilities
Russian-linked threat actor Head Mare compromised TrueConf Server by exploiting two critical unpatched vulnerabilities (KLCERT-26-057 and KLCERT-26-058), gaining SYSTEM-level privileges through an unauthenticated connection on port 4307/TCP. The attackers planted a PHP web shell and replaced legitimate TrueConf client installers with malicious unsigned versions containing the PhantomCore backdoor. Kaspersky confirmed active attacks in July 2026, with the malware using a Microsoft OneDrive account for command-and-control communications via the PhantomGraph component. TrueConf released patched versions 5.3.9, 5.4.9, and 5.5.5 on June 18, 2026, to address the flaws. Administrators are advised to update immediately, as the attack extends beyond server compromise into the software supply chain, silently infecting endpoints that download what appears to be a routine client update.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in