Threat Advisory

Head Mare Compromises TrueConf Servers While Targeting Conferencing Platforms with PhantomCore Backdoor

Threat: Vulnerability/Malware
Threat Actor Name: Head Mare
Targeted Region: Russia
Targeted Sector: Technology & IT, Energy & Utilities, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A targeted cyberattack by the Head Mare group has compromised vulnerable TrueConf Server deployments by exploiting CVE-2026-72529 and CVE-2026-72530 to establish access and distribute backdoored TrueConf Client installers. The campaign exploits weaknesses in outdated TrueConf Server versions, enabling attackers to execute malicious code with elevated privileges and compromise systems used for video conferencing. The attackers subsequently replace legitimate client installers with trojanized versions containing the PhantomCore backdoor, creating a potential supply-chain infection path for users connecting to compromised servers.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A targeted cyberattack by the Head Mare group has compromised vulnerable TrueConf Server deployments by exploiting CVE-2026-72529 and CVE-2026-72530 to establish access and distribute backdoored TrueConf Client installers. The campaign exploits weaknesses in outdated TrueConf Server versions, enabling attackers to execute malicious code with elevated privileges and compromise systems used for video conferencing. The attackers subsequently replace legitimate client installers with trojanized versions containing the PhantomCore backdoor, creating a potential supply-chain infection path for users connecting to compromised servers.[emaillocker id="1283"]

The attack involved compromising TrueConf servers and replacing legitimate client installation packages with malicious versions. When users downloaded and installed the altered software, the installer deployed the PhantomPxPigeon backdoor onto the victim system, providing attackers with remote access and the ability to conduct further malicious activity. The compromised servers were associated with organizations across multiple sectors, increasing the potential reach of the campaign beyond the initially breached environments. The exact mechanism used to compromise the TrueConf servers remains unclear, although exploitation of a previously addressed TrueConf Server vulnerability has been considered a possible intrusion vector. Malicious installers identified during the investigation lacked a valid TrueConf digital signature, providing a useful indicator for detecting tampered software packages.

The campaign demonstrates how exploitation of an exposed collaboration server can progress from server compromise to malware distribution through trusted software channels. Organizations operating affected TrueConf Server versions should upgrade to fixed releases, verify the digital signatures and integrity of TrueConf Client installers, and investigate systems that have obtained installation packages from potentially compromised servers. Security teams should also monitor for suspicious TrueConf-generated files and processes, unauthorized web-shell activity, unusual registry entries, PhantomCore or PhantomGraph artifacts, LSASS access, and unexpected SSH tunneling to identify potential compromise.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application -
Execution T1203 Exploitation for Client Execution -
Persistence T1543.003 Create or Modify System Process Windows Service
T1546.015 Event Triggered Execution Component Object Model Hijacking
Stealth T1027.002 Obfuscated Files or Information Software Packing
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

 

RECOMMENDATION:

  • We recommend you to update TrueConf Server to versions 5.3.9, 5.4.9 or 5.5.5 or later.

 

REFERENCES:

The following reports contain further technical details:

https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/

[/emaillocker]
crossmenu