Hackers Breach TrueConf, Inject Backdoors into Client Installers

Photo: BleepingComputer
Quick answer
The Head Mare hacking group breached TrueConf servers by exploiting critical vulnerabilities to replace client installers with PhantomCore and PhantomGraph backdoors.
The Head Mare cybercriminal group has launched a series of attacks on TrueConf video conferencing servers by exploiting unpatched vulnerabilities to distribute malicious client installers. Attackers gained access to systems through the default open TCP port 4307, then exploited two critical vulnerabilities: KLCERT-26-057 (arbitrary code execution) and KLCERT-26-058 (sandbox escape).
After successful intrusion, the attackers escalated privileges to NT AUTHORITY\SYSTEM and replaced the locale.php file with a web shell to ensure persistent remote access. Their primary goal was to replace the legitimate TrueConf Client installer with a backdoored version containing PhantomCore. Employees connecting to the compromised server receive a trojanized installer lacking a digital signature.
In addition to PhantomCore, hackers deploy the PhantomGraph backdoor, consisting of two DLL files. It communicates with the command center via Microsoft OneDrive*, executing commands and transmitting results. The group’s activities include dumping LSASS process memory to steal credentials, conducting network reconnaissance, and establishing reverse SSH tunnels.
The Head Mare attacks target Russian companies across sectors including energy, transportation, IT, and software development. Kaspersky Lab experts note that the group employs multiple initial access vectors: phishing, exploitation of vulnerabilities in public web servers, and attacks through contractors.
TrueConf has already patched the vulnerabilities in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18. Organizations are urged to update servers immediately and inspect client applications for signs of compromise. Earlier, in April 2026, Check Point Research reported another campaign exploiting a zero-day vulnerability in TrueConf (CVE-2026-3502), linked to Chinese hackers.
Common questions
- Which vulnerabilities did hackers exploit in the TrueConf attacks?
- Attackers exploited two critical vulnerabilities: KLCERT-26-057 (arbitrary code execution) and KLCERT-26-058 (sandbox escape). Both were patched in TrueConf Server updates released on June 18.
- What backdoors are deployed through compromised TrueConf installers?
- The attacks involve PhantomCore and PhantomGraph backdoors. PhantomCore is embedded in client installers, while PhantomGraph operates via DLL files and communicates with the command center through Microsoft OneDrive*.
- How can organizations protect themselves from TrueConf attacks?
- Organizations should update servers to versions 5.3.9, 5.4.9, or 5.5.5, verify client application integrity, and restrict access to port 4307. Monitoring suspicious network activity is also recommended.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml