Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TrueConf Server Vulnerabilities Exploited by Cybercriminals

TrueConf Server Vulnerabilities Exploited by Cybercriminals

Posted on August 10, 2026 By CWS

TrueConf Server Exploits Uncovered

A group of cybercriminals known as Head Mare has been actively exploiting vulnerabilities in TrueConf servers to target diverse Russian industries. The sectors affected include instrumentation, electronics, transport, energy, IT, and software development. Kaspersky, a Russian cybersecurity firm, identified these attacks in July 2026, emphasizing the need for immediate attention to these security breaches.

Exploiting TrueConf Vulnerabilities

The attackers have been taking advantage of a series of vulnerabilities in the TrueConf videoconferencing server. These vulnerabilities, labeled KLCERT-26-057 and KLCERT-26-058, allow the execution of arbitrary code with elevated privileges. They specifically impact TrueConf server versions 5.3.x to 5.3.9, 5.4.x to 5.4.9, and 5.5.x to 5.5.5, and earlier versions. The exploitation process involves replacing legitimate TrueConf client installers with compromised versions that install the PhantomCore backdoor and a remote access trojan (RAT).

The attack sequence begins with connecting to the TrueConf server via TCP port 4307, which is open by default. The attackers then exploit KLCERT-26-057 to execute malicious scripts within an isolated environment. This isolation restricts server access to operating system functions. Moving past this, KLCERT-26-058 is used to escape the confined environment, permitting arbitrary commands on the host server. These actions culminate in the replacement of specific server files with a web shell, allowing persistent remote access.

Impact and Measures

The web shell is used to gather data on IT infrastructure and gain enhanced access to the TrueConf database. This access facilitates the substitution of the original TrueConf client with an infected variant containing PhantomCore. This web shell also acts as a channel for another backdoor, PhantomGraph, which shares code similarities with PhantomCore. PhantomGraph consists of two DLL modules, SysExcSvc.dll and SysReadSvc.dll, aiding in command reception and execution.

To secure a lasting foothold, attackers employ a Base64-encoded PowerShell command to install these DLLs as Windows services. This strategic division of malware components aims to evade detection by EDR tools. Additionally, attackers establish an SSH reverse tunnel, extract memory dumps from critical processes, and utilize commands to gather general system information.

Ongoing Threats and Prevention

The flaws have been addressed in the latest TrueConf Server versions released on June 18, 2026. Users are advised to update to these versions to ensure maximum protection. This is not the first instance of Head Mare exploiting zero-day flaws in TrueConf to target Russian organizations. Earlier in the year, several vulnerabilities were manipulated for malicious purposes, highlighting the persistent threat posed by these actors.

In a related development, Kaspersky has uncovered a similar attack pattern involving the ViPNet product suite update mechanism. This ongoing attack, discovered in May 2026, targets various Russian sectors using a malicious DLL masquerading as part of the update system. The attack employs sophisticated techniques to infiltrate systems and execute payloads, emphasizing the need for robust cybersecurity measures.

The continued targeting of widely-used software in Russia underscores the growing threat landscape and the need for vigilance and timely updates to safeguard against advanced cyber threats.

The Hacker News Tags:Backdoor, Cybersecurity, Head Mare, IT infrastructure, Kaspersky, PhantomCore, remote access trojan, Russian companies, TrueConf, Vulnerabilities

Post navigation

Previous Post: Malicious Extension Mimics Google Translate, Compromises Browsers
Next Post: Cisco Discloses Critical ClamAV Vulnerabilities

Related Posts

FortiGate Exploits Highlight Ongoing Cyber Threats FortiGate Exploits Highlight Ongoing Cyber Threats The Hacker News
OAuth Consent: The New Phishing Threat Bypassing MFA OAuth Consent: The New Phishing Threat Bypassing MFA The Hacker News
Daxin Malware Reappears in Taiwan with New Stupig Backdoor Daxin Malware Reappears in Taiwan with New Stupig Backdoor The Hacker News
Stealthy DEAD#VAX Malware Uses AsyncRAT via IPFS VHDs Stealthy DEAD#VAX Malware Uses AsyncRAT via IPFS VHDs The Hacker News
Hackers Exploit Adform Script to Alter Crypto Wallets Hackers Exploit Adform Script to Alter Crypto Wallets The Hacker News
Chinese AI Firms Accused of Copying Claude Using 16 Million Queries Chinese AI Firms Accused of Copying Claude Using 16 Million Queries The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected
  • Cisco Discloses Critical ClamAV Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected
  • Cisco Discloses Critical ClamAV Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark