Head Mare Exploits TrueConf Vulnerabilities to Distribute Backdoored Installers

The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers by exploiting vulnerabilities tracked as KLCERT-26-057 and KLCERT-26-058, replacing legitimate installers with malware-laden versions. The attackers gain initial access via TCP port 4307, escalate privileges to NT AUTHORITY\SYSTEM, and deploy a web shell through the locale.php file for persistent remote access. They then replace the genuine TrueConf client installer on the server with a trojanized version containing the PhantomCore backdoor, along with two additional backdoors named PhantomGraph that can communicate through Microsoft OneDrive.

Employees connecting to compromised servers, whether their own organization or a counterparty's, may receive malicious updates even if their organization does not use TrueConf. Observed post-compromise activity includes LSASS memory extraction for credential harvesting, reconnaissance commands, and reverse SSH tunneling. The campaign targets Russian organizations in sectors such as instrumentation, electronics, transportation, energy, IT, and software development. TrueConf patched the vulnerabilities in versions 5.3.9, 5.4.9, and 5.5.5 released on June 18. This follows a separate zero-day campaign in April 2026 where hackers exploited CVE-2026-3502 to distribute trojanized updates. Organizations using TrueConf are urged to patch immediately and verify the integrity of their client installers. The group has also used phishing and contractor access for initial intrusion.

Read more...

Read More

Got Something To Say?

Your email address will not be published.