The Head Mare APT group is conducting a targeted campaign against strategic Russian sectors by exploiting vulnerabilities KLCERT-26-057 and KLCERT-26-058 in unpatched TrueConf video conferencing servers. By compromising these servers, attackers successfully trojanize the official TrueConf client installers hosted on the platform. This facilitates a sophisticated supply-chain-style delivery mechanism where participants downloading the installer to join conferences inadvertently deploy the PhantomCore and PhantomGraph backdoors onto their endpoints. This technique effectively transforms a trusted communication infrastructure into a malware distribution hub, leading to full system compromise within critical industries including energy, transport, and software development.
-
Incident Overview: Targeted Campaign
- Focuses on high-value Russian organizational targets.
- Active detection timeline established in July 2026.
- Leverages trusted communication channels to bypass perimeter defenses.
-
Attack Vector: Vulnerability Exploitation
- Exploits unpatched TrueConf Server instances.
- Utilizes specific vulnerability chain: KLCERT-26-057 and KLCERT-26-058.
- Enables unauthorized modification of server-side assets and hosted files.
-
Payload Mechanics: Malware Delivery
- Employs trojanized official TrueConf client installers.
- Delivers PhantomCore and PhantomGraph backdoor families.
- Targets endpoints during the legitimate conference-joining process.
-
Threat Profile: Target Sectors and Impact
- Primary targets include Energy, Transport, Electronics, and IT.
- Impact involves full system compromise via backdoor installation.
- Strategic emphasis on software development and instrumentation sectors.
-
Defensive Actions: Mitigation and Detection
- Immediate patching of TrueConf Server to latest secure versions is required.
- Implement strict file integrity monitoring (FIM) on all conference server assets.
- Monitor client endpoints for unauthorized connections to known C2 infrastructure associated with PhantomCore.
Related posts
- Securelist (Kaspersky) — Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
- bleepingcomputer.com — Hackers breach TrueConf to trojanize client installers with backdoors
- feeds.feedburner.com — TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
- F5
- Kaspersky
- Scworld
- Gurucul
- Safestate
- Buttondown