VMTech
Discuss a project

Head Mare uses TrueConf flaws to poison client installers

Head Mare uses TrueConf flaws to poison client installers

Kaspersky detected Head Mare exploiting unpatched TrueConf Server vulnerabilities in July 2026 to replace legitimate TrueConf Client installers with poisoned versions delivering the PhantomCore backdoor. The campaign targeted Russian organizations in instrumentation, electronics, transport, energy, IT and software development.

The attack affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier releases. TrueConf released patched versions 5.3.9, 5.4.9 and 5.5.5 on June 18, 2026.

Two flaws provide SYSTEM-level execution

Attackers connect to TCP port 4307, which is open by default, and exploit KLCERT-26-057 to run a malicious script. Although that script starts in an isolated server environment, KLCERT-26-058 enables the actors to escape it and execute commands on the underlying host.

The resulting access runs with NT AUTHORITY\SYSTEM privileges. The attackers replace ...\public\js\locale.php with a web shell, maintaining remote access while collecting infrastructure information and obtaining privileged access to the TrueConf database.

That database access enables substitution of the official client distribution with an infected installer containing PhantomCore. This installer-tampering approach is part of a wider pattern in which trusted software and update paths become an initial delivery mechanism, as ClickFix chains and software vulnerabilities also examined through ClickFix chains and software vulnerabilities.

PhantomGraph extends persistence and control

Kaspersky also identified PhantomGraph, a backdoor with code overlap with PhantomCore. Its SysExcSvc.dll module receives commands and sends results to Microsoft OneDrive used as command-and-control, while SysReadSvc.dll parses and executes those commands and stores the output.

Head Mare installs the two DLLs as Windows services through a Base64-encoded PowerShell command. Kaspersky said the split design appears intended to make detection by endpoint detection and response tools more difficult. The attackers also launched an SSH reverse tunnel, captured an lsass.exe memory dump, and ran commands including hostname and whoami.

Patch servers and validate client distribution

TrueConf users should move to the patched releases, review exposure of TCP port 4307, and investigate unauthorized changes to locale.php, server databases and client installer files. For businesses, the practical priority is to treat the conferencing server and its software distribution channel as one security boundary, validating both server patch status and the integrity of installers obtained by employees.

#cybersecurity#trueconf#malware#vulnerability
Open analytics
On the site 3 views
min read 3 10.08.2026
Instagram

Head Mare uses TrueConf flaws to poison client installers

Open the post on Instagram ↗