A critical vulnerability in TrueConf video conferencing servers has been exploited by hackers to deliver backdoors and compromise sensitive data. The Head Mare hacktivist group is behind the attacks, which have targeted organizations in various sectors, including enterprise and government entities in Russia.
The attackers took advantage of unpatched vulnerabilities in TrueConf Server versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions. They used TCP port 4307, which is open by default, to connect to the target server without authentication. Once inside, they executed a malicious script within TrueConf’s isolated environment, leveraging vulnerabilities tracked as KLCERT-26-057 and KLCERT-26-058.
The attackers then escalated their privileges to NT AUTHORITY\SYSTEM and replaced a key file with a web shell that granted them persistent remote access to the compromised server. They used this web shell to collect sensitive information from the victim’s environment, access the TrueConf database, and replace the legitimate client installer with a trojanized version containing the PhantomCore backdoor.
When users connect to the local TrueConf server, they receive a malicious installation package as an update. This is particularly concerning because even if an organization doesn’t use the compromised TrueConf server directly, its employees can still download infected packages from other affected servers by participating in online meetings.
The Head Mare hackers have also deployed PhantomGraph, a separate backdoor consisting of two DLL files that accept commands via a Microsoft OneDrive account. This malware has been observed dumping memory to exfiltrate credentials and running reconnaissance commands like hostname and whoami.
Kaspersky researchers are currently observing multiple active campaigns targeting Russian organizations in various sectors, including instrumentation, electronics, transportation, energy, IT, and software development. The attackers are using phishing, exploiting public-facing web servers, and contractor access as initial entry points.
It’s essential to note that TrueConf released patches for the exploited vulnerabilities on June 18, but many organizations may still be running outdated versions of the server. If you’re a TrueConf user, it’s crucial to update your server immediately and ensure all software is up-to-date.
The attack highlights the importance of regular vulnerability scanning and patch management. Even with robust security measures in place, attackers can still find ways to exploit vulnerabilities if they’re not properly addressed. As Kaspersky warns, “Even if your organization doesn’t use the TrueConf server directly, employees can still be affected by downloading infected installation packages from other compromised servers.”
Source: Bleeping Computer — 2026-08-08