← Back to Daily Briefing (#FBI)

The Head Mare APT group is conducting a targeted campaign against strategic Russian sectors by exploiting vulnerabilities KLCERT-26-057 and KLCERT-26-058 in unpatched TrueConf video conferencing servers. By compromising these servers, attackers successfully trojanize the official TrueConf client installers hosted on the platform. This facilitates a sophisticated supply-chain-style delivery mechanism where participants downloading the installer to join conferences inadvertently deploy the PhantomCore and PhantomGraph backdoors onto their endpoints. This technique effectively transforms a trusted communication infrastructure into a malware distribution hub, leading to full system compromise within critical industries including energy, transport, and software development.

  • Incident Overview: Targeted Campaign

    • Focuses on high-value Russian organizational targets.
    • Active detection timeline established in July 2026.
    • Leverages trusted communication channels to bypass perimeter defenses.
  • Attack Vector: Vulnerability Exploitation

    • Exploits unpatched TrueConf Server instances.
    • Utilizes specific vulnerability chain: KLCERT-26-057 and KLCERT-26-058.
    • Enables unauthorized modification of server-side assets and hosted files.
  • Payload Mechanics: Malware Delivery

    • Employs trojanized official TrueConf client installers.
    • Delivers PhantomCore and PhantomGraph backdoor families.
    • Targets endpoints during the legitimate conference-joining process.
  • Threat Profile: Target Sectors and Impact

    • Primary targets include Energy, Transport, Electronics, and IT.
    • Impact involves full system compromise via backdoor installation.
    • Strategic emphasis on software development and instrumentation sectors.
  • Defensive Actions: Mitigation and Detection

    • Immediate patching of TrueConf Server to latest secure versions is required.
    • Implement strict file integrity monitoring (FIM) on all conference server assets.
    • Monitor client endpoints for unauthorized connections to known C2 infrastructure associated with PhantomCore.

Related posts

  1. Securelist (Kaspersky) — Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
  2. bleepingcomputer.com — Hackers breach TrueConf to trojanize client installers with backdoors
  3. feeds.feedburner.com — TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
  4. F5
  5. Kaspersky
  6. Scworld
  7. Gurucul
  8. Safestate
  9. Buttondown

LINK COPIED TO CLIPBOARD