EXECUTIVE SUMMARY:
A targeted cyberattack by the Head Mare group has compromised vulnerable TrueConf Server deployments by exploiting CVE-2026-72529 and CVE-2026-72530 to establish access and distribute backdoored TrueConf Client installers. The campaign exploits weaknesses in outdated TrueConf Server versions, enabling attackers to execute malicious code with elevated privileges and compromise systems used for video conferencing. The attackers subsequently replace legitimate client installers with trojanized versions containing the PhantomCore backdoor, creating a potential supply-chain infection path for users connecting to compromised servers.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A targeted cyberattack by the Head Mare group has compromised vulnerable TrueConf Server deployments by exploiting CVE-2026-72529 and CVE-2026-72530 to establish access and distribute backdoored TrueConf Client installers. The campaign exploits weaknesses in outdated TrueConf Server versions, enabling attackers to execute malicious code with elevated privileges and compromise systems used for video conferencing. The attackers subsequently replace legitimate client installers with trojanized versions containing the PhantomCore backdoor, creating a potential supply-chain infection path for users connecting to compromised servers.[emaillocker id="1283"]
The attack involved compromising TrueConf servers and replacing legitimate client installation packages with malicious versions. When users downloaded and installed the altered software, the installer deployed the PhantomPxPigeon backdoor onto the victim system, providing attackers with remote access and the ability to conduct further malicious activity. The compromised servers were associated with organizations across multiple sectors, increasing the potential reach of the campaign beyond the initially breached environments. The exact mechanism used to compromise the TrueConf servers remains unclear, although exploitation of a previously addressed TrueConf Server vulnerability has been considered a possible intrusion vector. Malicious installers identified during the investigation lacked a valid TrueConf digital signature, providing a useful indicator for detecting tampered software packages.
The campaign demonstrates how exploitation of an exposed collaboration server can progress from server compromise to malware distribution through trusted software channels. Organizations operating affected TrueConf Server versions should upgrade to fixed releases, verify the digital signatures and integrity of TrueConf Client installers, and investigate systems that have obtained installation packages from potentially compromised servers. Security teams should also monitor for suspicious TrueConf-generated files and processes, unauthorized web-shell activity, unusual registry entries, PhantomCore or PhantomGraph artifacts, LSASS access, and unexpected SSH tunneling to identify potential compromise.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1190 | Exploit Public Facing Application | - |
| Execution | T1203 | Exploitation for Client Execution | - |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| T1546.015 | Event Triggered Execution | Component Object Model Hijacking | |
| Stealth | T1027.002 | Obfuscated Files or Information | Software Packing |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/
[/emaillocker]