TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

August 10, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Russian industrial and technology companies
Incident: Exploitation of TrueConf Server vulnerabilities to deploy PhantomCore and PhantomGraph malware via poisoned installers.
Impact: Full system compromise of servers and subsequent infection of client endpoints through a local supply chain attack.
Attacker: Head Mare (possibly a Chinese-speaking APT)
Analysis: The threat actor leverages a vulnerability chain to achieve full system privileges on TrueConf servers. By replacing legitimate client installers with poisoned versions, they distribute the PhantomCore and PhantomGraph malware to unsuspecting users. The use of split DLLs and Microsoft OneDrive for command-and-control indicates a sophisticated attempt to evade EDR detection.
Recommendations: Update TrueConf Server to versions 5.3.9, 5.4.9, or 5.5.5 immediately.; Audit server web directories for unauthorized modifications to locale.php.; Monitor for suspicious outbound traffic to Microsoft OneDrive from server infrastructure.
Source: The Hacker News / Kaspersky

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *