The threat group Head Mare exploited two security vulnerabilities in unpatched TrueConf videoconferencing servers to attack Russian organizations across instrumentation, electronics, transportation, energy, IT, and software development industries, according to a report published by Kaspersky in August 2026. The cybersecurity firm identified the attacks in July 2026. The operation involved chaining two flaws—tracked as KLCERT-26-057 and KLCERT-26-058—to replace legitimate TrueConf client installers with infected versions that delivered the PhantomCore backdoor and remote access trojan into vulnerable systems.
The attack compromised TrueConf server versions 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier releases. Attackers connected to servers via TCP port 4307, which remains open by default, then leveraged KLCERT-26-057 to execute a malicious script within an isolated environment on the server. They subsequently used KLCERT-26-058 to escape that isolated environment and run arbitrary commands on the underlying host with NT AUTHORITY\SYSTEM privileges. The attackers replaced the file "...\public\js\locale.php" with a web shell to maintain persistent remote access to compromised servers. The web shell collected intelligence on IT infrastructure, obtained privileged database access, and ultimately swapped original TrueConf Client distributions with infected versions containing PhantomCore. The web shell also served as a delivery mechanism for a second backdoor called PhantomGraph, which shares code overlap with PhantomCore and consists of two DLL modules: "SysExcSvc.dll," which receives commands and exfiltrates results to Microsoft OneDrive cloud storage used as command-and-control infrastructure, and "SysReadSvc.dll," which parses received commands, executes them, and stores the results. "We believe the attackers deliberately split this malware into two components to make it harder for EDR tools to detect," the report states. The threat actors also launched SSH reverse tunnels, captured memory dumps of the "lsass.exe" process, and gathered system information using commands like hostname and whoami.
The vulnerabilities were patched by TrueConf in the latest server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026, meaning the July attacks targeted organizations that had not yet updated. This marks the second documented instance of Head Mare targeting zero-day flaws in TrueConf to strike Russian entities. In April 2026, Positive Technologies disclosed that three separate vulnerabilities in the software—BDU:2025-10114, BDU:2025-10115, and BDU-2025-10116—were exploited by the group starting in September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution. Around the same time, Check Point reported that another high-severity security flaw in the TrueConf client, CVE-2026-3502, was exploited in the wild as a zero-day in a campaign targeting government entities in Southeast Asia to deploy the Havoc C2 framework. The repeated exploitation of TrueConf software suggests the platform has become a preferred attack vector for advanced threat actors targeting Russian infrastructure, with the software's widespread deployment in the country creating a broad attack surface for groups seeking persistent access to sensitive networks.
Organizations using TrueConf are advised to download the latest versions for optimal protection, the report concludes. Kaspersky also disclosed a separate advanced persistent threat-style attack ongoing since at least May 2026 that hijacked the update mechanism for the ViPNet product suite to target Russian government, energy, transport, education, and logistics sectors with previously unreported tools dubbed HelloInjector and HelloProxy. The dual campaigns against widely-used Russian software platforms highlight how nation-state and advanced threat actors are increasingly focusing on supply chain and update mechanisms to achieve initial access and persistence. The fragmentation of widely deployed enterprise tools into competing update and patch schedules creates windows of vulnerability that sophisticated attackers can exploit before organizations apply fixes, particularly when zero-day flaws allow attacks before patches even exist.

