TrueConf Server Exploits Uncovered
A group of cybercriminals known as Head Mare has been actively exploiting vulnerabilities in TrueConf servers to target diverse Russian industries. The sectors affected include instrumentation, electronics, transport, energy, IT, and software development. Kaspersky, a Russian cybersecurity firm, identified these attacks in July 2026, emphasizing the need for immediate attention to these security breaches.
Exploiting TrueConf Vulnerabilities
The attackers have been taking advantage of a series of vulnerabilities in the TrueConf videoconferencing server. These vulnerabilities, labeled KLCERT-26-057 and KLCERT-26-058, allow the execution of arbitrary code with elevated privileges. They specifically impact TrueConf server versions 5.3.x to 5.3.9, 5.4.x to 5.4.9, and 5.5.x to 5.5.5, and earlier versions. The exploitation process involves replacing legitimate TrueConf client installers with compromised versions that install the PhantomCore backdoor and a remote access trojan (RAT).
The attack sequence begins with connecting to the TrueConf server via TCP port 4307, which is open by default. The attackers then exploit KLCERT-26-057 to execute malicious scripts within an isolated environment. This isolation restricts server access to operating system functions. Moving past this, KLCERT-26-058 is used to escape the confined environment, permitting arbitrary commands on the host server. These actions culminate in the replacement of specific server files with a web shell, allowing persistent remote access.
Impact and Measures
The web shell is used to gather data on IT infrastructure and gain enhanced access to the TrueConf database. This access facilitates the substitution of the original TrueConf client with an infected variant containing PhantomCore. This web shell also acts as a channel for another backdoor, PhantomGraph, which shares code similarities with PhantomCore. PhantomGraph consists of two DLL modules, SysExcSvc.dll and SysReadSvc.dll, aiding in command reception and execution.
To secure a lasting foothold, attackers employ a Base64-encoded PowerShell command to install these DLLs as Windows services. This strategic division of malware components aims to evade detection by EDR tools. Additionally, attackers establish an SSH reverse tunnel, extract memory dumps from critical processes, and utilize commands to gather general system information.
Ongoing Threats and Prevention
The flaws have been addressed in the latest TrueConf Server versions released on June 18, 2026. Users are advised to update to these versions to ensure maximum protection. This is not the first instance of Head Mare exploiting zero-day flaws in TrueConf to target Russian organizations. Earlier in the year, several vulnerabilities were manipulated for malicious purposes, highlighting the persistent threat posed by these actors.
In a related development, Kaspersky has uncovered a similar attack pattern involving the ViPNet product suite update mechanism. This ongoing attack, discovered in May 2026, targets various Russian sectors using a malicious DLL masquerading as part of the update system. The attack employs sophisticated techniques to infiltrate systems and execute payloads, emphasizing the need for robust cybersecurity measures.
The continued targeting of widely-used software in Russia underscores the growing threat landscape and the need for vigilance and timely updates to safeguard against advanced cyber threats.
