Head Mare APT Exploits TrueConf Server Vulnerabilities to Deploy PhantomCore and PhantomGraph
The Head Mare APT group is conducting a targeted campaign against strategic Russian sectors by exploiting vulnerabilities KLCERT-26-057 and KLCERT-26-058 in unpatched TrueConf video conferencing servers. By compromising these servers, attackers successfully trojanize the official TrueConf client installers hosted on the platform. This facilitates a sophisticated supply-chain-style delivery mechanism where participants downloading the installer to join conferences inadvertently deploy the PhantomCore and PhantomGraph backdoors onto their endpoints. This technique effectively transforms a trusted communication infrastructure into a malware distribution hub, leading to full system compromise within critical industries including energy, transport, and software development.