
Head Mare Breaches TrueConf Servers to Spread Backdoor
The Head Mare hacktivist group has exploited vulnerabilities in unpatched TrueConf video conferencing servers, replacing legitimate client installers with malicious versions that deliver the PhantomCore backdoor. TrueConf is widely used in Russia, particularly by enterprises and government organizations as an on-premise alternative to platforms such as Zoom and Microsoft Teams. Kaspersky researchers discovered the attack in July. They found that the hackers used TCP port 4307, which is open by default, to connect to targeted TrueConf servers without authentication. The KLCERT-26-057 vulnerability allowed them to execute a malicious script inside TrueConf’s isolated environment, while KLCERT-26-058 enabled them to escape that sandbox and run commands on the underlying operating system. The attackers escalated their privileges to NT AUTHORITY\SYSTEM and replaced the '\public\js\locale.php' file with a web shell that provided persistent remote access. Kaspersky said the web shell was used to collect sensitive information, access the TrueConf database and replace the legitimate TrueConf Client installer hosted on the server with a version containing PhantomCore. When members of an organization connect to its local TrueConf server, they can receive the trojanized, unsigned installer as an update. Kaspersky warned that employees whose organizations do not operate TrueConf servers may still be exposed if they join meetings on a compromised partner’s server and download an infected installation package. Activity observed through the PhantomGraph backdoor included dumping memory from the Local Security Authority Subsystem Service process to steal credentials, running reconnaissance commands such as 'hostname' and 'whoami', and starting a reverse SSH tunnel. Kaspersky said it is observing several active Head Mare campaigns against Russian organizations in instrumentation, electronics, transportation, energy, IT and software development. The flaws affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions. The vendor fixed them in versions 5.3.9, 5.4.9 and 5.5.5, released on June 18. CheckPoint Research also reported a separate TrueConf campaign in April 2026, named Operation True Chaos. The exposure does not end with the organization hosting the server: an ordinary meeting with a business partner can become a route for a malicious installer. Somali organizations working with partners abroad should therefore scrutinize software offered for download when joining online meetings.
Read our sourcing and corrections policy



Be the first to comment on this story!