The Head Mare hacktivist group has been targeting unpatched True Conf video conferencing enterprise servers to replace legitimate client installers with malware-containing versions, Kaspersky said.
TrueConf is a business communication tool popular in Russia among enterprises and government agencies as an on-premise alternative to western video conferencing products like Zoom and Microsoft Teams.
Kaspersky researchers discovered the attacks in July and identified that Head Mare hackers used TCP port 4307, which is open by default, to connect to the target TrueConf servers without authentication, and exploit the vulnerabilities KLCERT-26-057 and KLCERT-26-058, which have been tracked by KLCERT. They allowed the attackers to run a malicious script in an isolated TrueConf environment, bypass the sandbox and execute commands on the underlying operating system.
The attackers then elevated their privileges to NT AUTHORITY\SYSTEM and replaced the \public\js\locale.php file with a web shell, which provided persistent remote access to the compromised server.
Kaspersky said that Head Mare uses the web shell to collect sensitive information and access the TrueConf database and replace the legitimate TrueConf Client installer on the server with a malicious version containing the PhantomCore backdoor.
When members of an organization connect to a compromised local TrueConf server, they can receive the trojanized installer as an update.
Kaspersky also warned that employees could be exposed even if their own organization does not use TrueConf. Employees connecting to compromised TrueConf servers operated by counterparties to participate in online meetings can download infected installation packages.
Head Mare also deploys PhantomGraph, another backdoor consisting of two dll files: SysExcSvc.dll and SysReadSvc.dll.
The malware is capable of receiving commands through a Microsoft OneDrive account, executing these commands and returning the results. Observed activity comprised extracting the memory of the Local Security Authority Subsystem Service (LSASS) process to extract credentials, conducting reconnaissance by executing commands such as hostname and whoami, and establishing a reverse SSH tunnel.
Kaspersky said that it is observing multiple active Head Mare campaigns targeting Russian organizations in instrumentation, electronics, transportation, energy, IT and software development.
The group has used phishing, exploitation of public facing web servers and access through contractors as initial access methods.
The exploited TrueConf vulnerabilities affected versions 5.3.x before 5.3.9, 5.4.x before 5.4.9 and 5.5.x before 5.5.5, as well as older versions. TrueConf fixed the vulnerabilities in versions 5.3.9, 5.4.9 and 5.5.5, which were released on June 18.
The attacks followed another campaign reported by Check Point Research in April 2026, in which hackers exploited a zero-day arbitrary file execution vulnerability in TrueConf, tracked as CVE-2026-3502, to compromise users through trojanized client updates.
Read the original article: