Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Target TrueConf Servers with Malware

Hackers Target TrueConf Servers with Malware

Posted on August 21, 2026 By CWS

Security researchers from Kaspersky have identified a significant cyber threat targeting TrueConf video conferencing software. The investigation revealed that software installers, believed to be legitimate by users, were bundled with PhantomCore malware. This malicious activity is linked to the Head Mare APT group, exploiting vulnerabilities in Russian organizations.

TrueConf Servers Leveraged for Malware Distribution

The attackers manipulated TrueConf servers to distribute compromised software directly, making downloads appear trustworthy to unsuspecting employees. By exploiting two specific vulnerabilities, labeled KLCERT-26-057 and KLCERT-26-058, the hackers managed to execute harmful code on these servers.

The first vulnerability allowed unauthorized access through port 4307/TCP, enabling attackers to run illicit scripts. The second flaw provided the means to escape an isolated environment, granting attackers system-level privileges. This access was used to replace genuine server files with malicious web shells, facilitating further infiltration into the victim’s IT infrastructure.

Impact on Windows and Linux Systems

On Windows machines, the attackers installed backdoor services named SysExcSvc and SysReadSvc, using Microsoft OneDrive for command and control communication. Linux systems were similarly compromised through a backdoor that intercepted TrueConf network traffic, utilizing GitHub for remote operations. Users joining video calls on affected servers received prompts to download a new client application, which secretly installed malware alongside the legitimate software.

A registry key was created to ensure the malware’s persistence through system reboots. Kaspersky warns that organizations using TrueConf servers, as well as those participating in meetings on third-party compromised servers, are at risk.

Mitigation and Response Strategies

TrueConf has addressed these vulnerabilities in server versions 5.3.9, 5.4.9, and 5.5.5, released on June 18, 2026. Kaspersky’s analysis showed that all server versions released since 2022 were vulnerable before this patch. Administrators are urged to update their systems promptly and monitor for signs of compromise using indicators provided by Kaspersky.

Security teams should conduct thorough antivirus scans and reset passwords for potentially exposed accounts. If indicators of compromise are detected, contacting Kaspersky’s ICS CERT team is recommended for further investigation and support.

This incident underscores the risks associated with software supply chains, where trusted applications can become vectors for extensive system breaches. A detailed analysis and further findings are anticipated in an upcoming Kaspersky Threat Intelligence report.

Cyber Security News Tags:APT group, backdoor services, Cybersecurity, IT security, Kaspersky, Malware, malware distribution, network breach, PhantomCore, remote access, server exploitation, software update, TrueConf, video conferencing, Vulnerabilities

Post navigation

Previous Post: Microsoft Releases 22 Security Updates for Critical Flaws
Next Post: North Korean Hackers Target Rust Software Supply Chain

Related Posts

OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices Cyber Security News
Microsoft Investigating Boot Failure Issues With Windows 11, version 25H2 Following January Update Microsoft Investigating Boot Failure Issues With Windows 11, version 25H2 Following January Update Cyber Security News
“GPUGate” Malware Abuses Uses Google Ads and GitHub to Deliver Advanced Malware Payload “GPUGate” Malware Abuses Uses Google Ads and GitHub to Deliver Advanced Malware Payload Cyber Security News
Exploited PaperCut Server Breach Exposes Critical Flaws Exploited PaperCut Server Breach Exposes Critical Flaws Cyber Security News
MacOS Malware NimDoor Weaponizing Zoom SDK Update to Steal Keychain Credentials MacOS Malware NimDoor Weaponizing Zoom SDK Update to Steal Keychain Credentials Cyber Security News
GitLost Flaw Exposes GitHub Repos via AI Workflow GitLost Flaw Exposes GitHub Repos via AI Workflow Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Update Causes App Crashes Due to Audio Bug
  • Healthcare Firms in NJ and TX Suffer Major Data Breaches
  • Phishing Scams Exploit ScreenConnect for Remote Access
  • Rejetto HFS Vulnerability Exploited, AI Identifies Flaw
  • Apple Tightens macOS Disk Access to Protect Against AI Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Update Causes App Crashes Due to Audio Bug
  • Healthcare Firms in NJ and TX Suffer Major Data Breaches
  • Phishing Scams Exploit ScreenConnect for Remote Access
  • Rejetto HFS Vulnerability Exploited, AI Identifies Flaw
  • Apple Tightens macOS Disk Access to Protect Against AI Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark