Head Mare Exploits TrueConf Flaws to Deliver PhantomCore Malware to Meeting Participants

The Head Mare advanced persistent threat group has been exploiting unpatched TrueConf Server instances to distribute the PhantomCore backdoor to video-conference participants.

The campaign transforms compromised enterprise collaboration servers into malware-delivery infrastructure, putting not only TrueConf administrators at risk but also employees and contractors who join hosted meetings and download the client application.

Kaspersky discovered the activity while investigating attacks targeting Russian organizations. The attackers compromised TrueConf servers and replaced the legitimate Windows x64 client distribution file with a trojanized installer.

Head Mare Exploits TrueConf Flaws

When a conference participant visits the meeting guest page, they are prompted to download or update the TrueConf client. The modified package still installs the expected conferencing software, reducing suspicion, but also deploys PhantomCore onto the victim’s workstation,

 Guest page for joining a conference (Source: Kaspersky)
 Guest page for joining a conference (Source: Kaspersky)

The intrusion chain relies on two vulnerabilities tracked as KLCERT-26-057 and KLCERT-26-058. The first flaw allows an unauthenticated attacker to connect through TCP port 4307, which is open by default on TrueConf Server, and invoke an undocumented function to execute a malicious script.

Kaspersky said the issue affects releases in the 5.3.X, 5.4.X, and 5.5.X branches before versions 5.3.9, 5.4.9, and 5.5.5, respectively. Researchers also determined that TrueConf Server versions released since 2022 were vulnerable.

While the initial script executes in an isolated environment that restricts potentially hazardous libraries such as io and os, Head Mare chains the second vulnerability to escape those controls.

This allows arbitrary code execution with NT AUTHORITY\SYSTEM privileges on affected Windows servers. With that access, the attackers replace C:\Program Files\TrueConf Server\httpconf\site\public\js\locale.php with a malicious web shell and remove event-log records associated with exploit activity.

The web shell enables infrastructure reconnaissance, privileged access to the TrueConf Server database, remote PowerShell execution, and replacement of the client installer stored at C:\Program Files\TrueConf Server\ClientInstFiles\trueconf_windows_client_x64.exe.

The group also installs a backup backdoor composed of communication and execution modules. These components communicate through a Microsoft OneDrive account and create persistence services named SysExcSvc and SysReadSvc.

On Unix-like servers, Head Mare deploys additional implants, including a backdoor that intercepts TrueConf network functions and receives operator commands through the TrueConf protocol.

Kaspersky also observed a Linux backdoor using GitHub as command-and-control infrastructure, illustrating the group’s use of legitimate services to mask malicious traffic.

The infected Windows installer drops PhantomCore to %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll.

The malware provides arbitrary command execution and persists through the HKCU\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 registry location.

TrueConf released security updates 5.3.9, 5.4.9, and 5.5.5 on June 18, 2026, and urged administrators to upgrade immediately. Organizations should hunt for Kaspersky’s published hashes, suspicious services, altered locale.php files, and unexpected PowerShell activity.

Companies should also rotate potentially exposed credentials, scan servers and endpoints with updated security tools, and treat externally hosted TrueConf meeting downloads as potentially unsafe until verified.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories