Kaspersky has discovered a new multi-stage attack by the Head Mare APT group against organisations with PhantomCore and PhantomGraph backdoors. To deliver these backdoors, the attackers exploit vulnerabilities in unpatched TrueConf videoconferencing servers and can also replace TrueConf client installers with infected ones.

Kaspersky reported the attacks to the vendor; the vulnerabilities were fixed in the latest TrueConf Server update on June 18, 2026 (versions 5.3.9, 5.4.9, and 5.5.5).
To compromise the TrueConf server, attackers exploited a combination of two vulnerabilities (assigned internal Kaspersky identifiers are KLCERT-26-057 and KLCERT-26-058), which allowed the attackers to execute any code with maximum privileges. By exploiting these vulnerabilities, they replaced one of the server's files with their own web shell.
The attackers then used this shell to collect information about the victim organisation's IT infrastructure, gain privileged access to the TrueConf server database, and replace the client installer with an infected one. The attack applies to TrueConf servers in versions 5.3.X prior to 5.3.9, 5.4.X prior to 5.4.9, 5.5.X prior to 5.5.5, and earlier.
For users of TrueConf software, the attack looks like this: video conference participants connecting to the compromised server are prompted to download and install an "updated version" of the client application. In reality, as a result of this, malware gets onto the device.
“Exploiting vulnerabilities in popular services is one of the most common methods used by attackers. This campaign is particularly dangerous because it puts at risk not only organisations using unpatched TrueConf servers.
“Even if a company doesn't use this solution, its employees can connect to compromised servers at the invitation of their counterparties to participate in online meetings. As a result, they may unknowingly download infected installation packages, creating the potential for compromising a large number of enterprises across different countries,” comments Evgeny Goncharov, Head of Kaspersky ICS CERT.










