Hackers breach TrueConf to trojanize client installers with backdoors

August 8, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: bleepingcomputer.com

Threat Risk: High
Victim: Russian enterprise and government sectors
Incident: Supply chain compromise of TrueConf servers to deliver trojanized client installers.
Impact: Full system compromise and credential theft via persistent backdoors.
Attacker: Head Mare (attributed to Chinese threat actors)
Analysis: The Head Mare group leverages critical vulnerabilities in TrueConf servers to gain system-level privileges and deploy web shells. By trojanizing official client installers hosted on the server, they ensure that any user updating their software is infected with PhantomCore and PhantomGraph backdoors. This method allows for persistent remote access and credential exfiltration across high-value government and enterprise sectors.
Recommendations: Update TrueConf Server to the latest patched versions (5.3.9+, 5.4.9+, or 5.5.5+).; Audit server directories for unauthorized modifications to the locale.php file.; Monitor for suspicious outbound traffic to Microsoft OneDrive and unauthorized use of TCP port 4307.
Source: Bleeping Computer

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *