Executive Summary
In July 2026, Kaspersky researchers identified that the Head Mare hacktivist group exploited a chain of vulnerabilities in unpatched TrueConf video conferencing servers, enabling attackers to replace legitimate client installers with trojanized versions containing the PhantomCore and PhantomGraph backdoors. The attack leveraged vulnerabilities tracked as KLCERT-26-057 and KLCERT-26-058, which allowed for arbitrary code execution with SYSTEM privileges, installation of web shells, and persistent backdooring of the environment. The attackers distributed a malicious, non-digitally signed TrueConf Client installer to users connecting to compromised servers, resulting in widespread risk of credential theft, lateral movement, and further compromise. The campaign primarily targeted Russian organizations in critical sectors such as instrumentation, electronics, transportation, energy, IT, and software development. Vendor patches were released on June 18, 2026, and multiple security advisories have since been published. All technical details and indicators of compromise in this report are based on direct evidence from Kaspersky and BleepingComputer.
Technical Information
The breach of TrueConf servers by the Head Mare group represents a sophisticated supply chain attack, exploiting two critical vulnerabilities (KLCERT-26-057 and KLCERT-26-058) in the TrueConf Server product. The attack chain began with unauthenticated access to TCP port 4307, which is open by default on vulnerable servers. Attackers exploited KLCERT-26-057 to execute a malicious script within the isolated TrueConf environment, then leveraged KLCERT-26-058 to escape the sandbox and execute operating system-level commands with SYSTEM privileges.
Once inside, the attackers deployed a PHP web shell (locale.php) to maintain access and facilitate further exploitation. They then replaced the legitimate TrueConf Client installer hosted on the server with a trojanized, non-digitally signed version. Any user connecting to the compromised server for updates or downloads received this malicious installer, which contained the PhantomCore and PhantomGraph backdoors.
PhantomCore is a DLL-based backdoor that provides attackers with system reconnaissance capabilities, credential theft (including LSASS memory dumping), and command and control (C2) communication. PhantomGraph (SysExcSvc.dll and SysReadSvc.dll) is another backdoor that communicates with attacker infrastructure via Microsoft OneDrive, blending malicious traffic with legitimate cloud storage activity. Both backdoors were installed as Windows services for persistence.
Persistence was further achieved through the creation of a registry key at HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32, and by installing the malicious DLLs as Windows services. The attackers also used reverse SSH tunnels for lateral movement within compromised environments.
Credential access was a key objective, with attackers dumping the memory of the LSASS process to exfiltrate credentials. Exfiltration and C2 communications were conducted over both custom malicious domains and IP addresses, as well as via OneDrive cloud storage.
The attack was mapped to multiple MITRE ATT&CK techniques, including T1190 (Exploit Public-Facing Application), T1566 (Phishing), T1199 (Trusted Relationship), T1505.003 (Web Shell), T1059 (Command and Scripting Interpreter), T1547.001 (Registry Run Keys/Startup Folder), T1574.002 (DLL Side-Loading), T1543.003 (Create or Modify System Process: Windows Service), T1068 (Exploitation for Privilege Escalation), T1553.002 (Subvert Trust Controls: Code Signing), T1102.002 (Web Service: Cloud Storage), T1003.001 (OS Credential Dumping: LSASS Memory), T1572 (Protocol Tunneling), T1071.001 (Application Layer Protocol: Web Protocols), and T1041 (Exfiltration Over C2 Channel).
The Head Mare group has a history of targeting Russian organizations in critical and high-tech sectors, often using supply chain and web shell tactics. The supply chain nature of this attack means that even organizations not directly operating TrueConf servers could be affected if their employees connect to compromised third-party servers for meetings.
Affected Versions & Timeline
The vulnerabilities exploited in this campaign affected TrueConf Server versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and all older versions. Vendor patches addressing these vulnerabilities were released on June 18, 2026. The attack campaign was observed in July 2026, with public disclosure and technical analysis published by Kaspersky on August 7, 2026, and by BleepingComputer on August 8, 2026.
Threat Activity
The Head Mare group conducted targeted campaigns against Russian organizations in sectors such as instrumentation, electronics, transportation, energy, IT, and software development. Initial access was achieved through exploitation of public-facing TrueConf servers, phishing, and access via compromised contractors. Once inside, attackers deployed web shells, replaced client installers, and established persistent backdoors. The use of trojanized installers enabled malware propagation to users both within and outside the directly targeted organizations, increasing the risk of credential theft, lateral movement, and further breaches. The attackers exfiltrated sensitive information, including database contents, credentials, and system reconnaissance data, and used reverse SSH tunnels for lateral movement.
Mitigation & Workarounds
The most critical mitigation is to immediately update all TrueConf Server installations to versions 5.3.9, 5.4.9, or 5.5.5, as these versions contain patches for the exploited vulnerabilities. Organizations should verify the digital signatures of all TrueConf Client installers before deployment or update, and ensure that only installers obtained directly from the official vendor are used. It is essential to monitor for the indicators of compromise listed below and to review endpoint and network logs for signs of unauthorized access or malware activity. Organizations should also be cautious of third-party meeting invitations and downloads, as the supply chain nature of the attack means that compromise can propagate through trusted relationships. Even organizations not directly using TrueConf servers should assess their exposure if employees participate in meetings hosted on external servers.
Indicators of Compromise
The following indicators are provided as a point-in-time reference and should be validated in your environment before enforcement. These IOCs are sourced directly from Kaspersky Securelist and BleepingComputer, with publication dates as noted.
Type | Indicator | Reported (date) | Source
|
MD5 | 4d27b4eb1c5dbb3d8160f29b8119523e | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
MD5 | 748c9f8cb1065000616204935f96207f | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
MD5 | c5a460e4e68a088f6e51b2c6474642ec | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
MD5 | 489f43be558b2679284ceabed7adc4f3 | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
MD5 | dd1fd2b459b97b7d59375cb8383cd19a | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | penzadogshelter[.]site | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | trendy-market[.]site | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | bright-deals[.]site | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | nova-stream[.]site | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | rinomobile[.]ink | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | urbanpixel[.]store | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | flexish[.]shop | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | media-hub[.]today | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | cosmetic-deals[.]store | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Domain | vks.gossopka[.]forum | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
IP | 81.177.32[.]12 | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
IP | 194.87.239[.]71 | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
IP | 194.87.93[.]153 | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
IP | 38.244.205[.]244 | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
IP | 31.59.102[.]61 | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
Registry | HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 | 2026-08-07 | https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/ |
References
BleepingComputer, August 8, 2026: https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/
Kaspersky Securelist, August 7, 2026: https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/
TrueConf Changelog, June 18, 2026: https://trueconf.com/products/changelog.html
About Rescana
Rescana provides a third-party risk management (TPRM) platform that enables organizations to continuously monitor their vendor ecosystem for emerging threats, supply chain vulnerabilities, and exposure to high-impact incidents. Our platform supports rapid identification of affected vendors and facilitates evidence-based risk assessments in response to incidents such as software supply chain attacks.
We are happy to answer questions at info@rescana.com.



