Hackers breach TrueConf to trojanize client installers with backdoors

A devastating cyberattack has been uncovered, with hackers breaching video conferencing servers from TrueConf, a tool widely used in Russia. The Head Mare hacktivist group has taken advantage of vulnerabilities in unpatched TrueConf servers to deliver backdoors and compromise sensitive information. This attack highlights the importance of patching software and staying vigilant against cyber threats.

The researchers at Kaspersky discovered that the attackers used TCP port 4307, which is open by default on TrueConf servers, to connect without authentication. They then exploited two vulnerabilities, internally tracked as KLCERT-26-057 and KLCERT-26-058, to execute malicious scripts within the isolated environment of the server. The attackers increased their privileges to NT AUTHORITY\SYSTEM and replaced a critical file with a web shell that granted them persistent remote access.

The compromised servers were then used to collect sensitive information from the victim’s environment, including accessing the TrueConf database. The most egregious part of this attack is that when employees connect to the local TrueConf server, they receive a trojanized client installer as an update, which contains the PhantomCore backdoor. Even if your organization doesn’t use the TrueConf server, employees can still be affected by connecting to compromised servers from other organizations.

The Head Mare group also deployed a separate backdoor called PhantomGraph, consisting of two DLL files that accept commands via a Microsoft OneDrive account and execute them. The malware is capable of dumping memory, executing reconnaissance commands like hostname and whoami, and even starting reverse SSH tunnels. Kaspersky has observed multiple active campaigns targeting Russian organizations in various sectors.

The two vulnerabilities exploited by the attackers were patched by TrueConf on June 18, but it’s likely that many servers remain unpatched, leaving them vulnerable to similar attacks. In April, CheckPoint Research reported a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502, which was used to compromise users via trojanized client updates.

The takeaway from this attack is clear: patching software and staying vigilant against cyber threats are crucial to preventing attacks like this. Organizations must ensure that all layers of their security stack are tested regularly to prevent vulnerabilities like these from going undetected. With 54% of successful attacks remaining undetected, it’s essential to invest in breach and attack simulation testing to fortify your defenses.


Source: Bleeping Computer — 2026-08-08