Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Sakura Internet Breach Exposes 1.36 Million Customer Records
August 21, 2026
OpenAI Rolls Out Zero Data Retention for Enterprise ChatGPT
August 21, 2026
DOJ Charges 17 Iranian Hackers in Massive Data Theft Campaign
August 21, 2026
Home/Vulnerabilities/Critical TrueConf Server Flaws Let Attackers Push Malware via Updates
Vulnerabilities

Critical TrueConf Server Flaws Let Attackers Push Malware via Updates

Key Takeaways The Head Mare APT group exploited critical vulnerabilities in TrueConf Server to distribute PhantomCore malware. Attackers leveraged two flaws (KLCERT-26-057 and KLCERT-26-058) to gain...

David kimber
David kimber
August 21, 2026 3 Min Read
3 0

Key Takeaways

  • The Head Mare APT group exploited critical vulnerabilities in TrueConf Server to distribute PhantomCore malware.
  • Attackers leveraged two flaws (KLCERT-26-057 and KLCERT-26-058) to gain full system control and push malicious updates.
  • Compromised TrueConf servers delivered infected client installers, impacting both Windows and Linux users.
  • TrueConf patched these vulnerabilities in server versions 5.3.9, 5.4.9, and 5.5.5, released on June 18, 2026.
  • Organizations must update immediately and scan for indicators of compromise.

Cybersecurity researchers at Kaspersky have uncovered a sophisticated campaign orchestrated by the advanced persistent threat (APT) group known as Head Mare. The group exploited critical vulnerabilities within TrueConf Server, a popular video conferencing solution, to covertly bundle its PhantomCore malware with legitimate client installers. These malicious packages were then distributed directly from compromised TrueConf servers belonging to victim organizations, lending a deceptive air of legitimacy to the downloads.

Table Of Content

  • Key Takeaways
  • Exploiting TrueConf Servers
  • Multi-Platform Malware Deployment
  • Patch and Remediation
  • What You Should Do

Exploiting TrueConf Servers

The attackers chained together two distinct vulnerabilities to achieve arbitrary code execution on TrueConf servers. Internally tracked by Kaspersky as KLCERT-26-057 and KLCERT-26-058, these flaws provided a pathway for the sophisticated attack.

The first vulnerability, KLCERT-26-057, allowed an unauthenticated attacker to connect to TCP port 4307 and invoke an undocumented function. This action facilitated the execution of a malicious script on the server. Subsequently, KLCERT-26-058 enabled attackers to bypass the isolated execution environment, escalating privileges to NT AUTHORITYSYSTEM. This critical step granted them complete control over the compromised server.

With system-level access secured, the threat actors replaced a legitimate server file with a malicious web shell. This web shell became their primary tool for mapping the victim’s IT infrastructure, gaining privileged access to databases, and ultimately substituting authentic client installers with their infected versions.

Multi-Platform Malware Deployment

The Head Mare group tailored its attack for different operating systems. On Windows systems, they deployed backdoor services named SysExcSvc and SysReadSvc. These services leveraged Microsoft OneDrive as a command-and-control (C2) channel for communication.

For Linux environments, a separate backdoor was utilized. This Linux-specific malware was designed to conceal its files, intercept TrueConf network traffic, and employ GitHub for its command-and-control infrastructure.

Users joining video calls hosted on a compromised TrueConf server were prompted to download a “new client application.” This installer silently deployed the legitimate TrueConf client alongside a hidden PhantomCore payload, disguised as a DLL. This granted attackers remote command execution capabilities and full control over the infected workstation. To ensure persistence, a registry key was created, guaranteeing the malware’s automatic launch at every system startup. Kaspersky warns that even organizations not directly operating TrueConf servers could be at risk if their employees join meetings hosted on compromised third-party or contractor servers.

Patch and Remediation

TrueConf addressed both vulnerabilities, releasing patches in server versions 5.3.9, 5.4.9, and 5.5.5 on June 18, 2026. Kaspersky’s internal analysis revealed that all TrueConf server versions released since 2022 were vulnerable prior to this patch. The vendor is actively informing administrators to update their systems immediately, while Kaspersky continues to coordinate disclosure efforts and provide remediation support.

What You Should Do

  • Update TrueConf Servers: Immediately update all TrueConf servers to patched versions 5.3.9, 5.4.9, or 5.5.5, or newer.
  • Scan for Indicators of Compromise (IoCs): Conduct thorough scans of your environment for the IoCs Kaspersky published. This includes specific file hashes (e.g., malicious TrueConf installer MD5: 748c9f8cb1065000616204935f96207f, PhantomCore MD5: c5a460e4e68a088f6e51b2c6474642ec), suspicious file paths (e.g., C:WindowsSystem32inetsrvSysExcSvc.dll), malicious domains (e.g., penzadogshelter[.]site), and unusual service names like SysExcSvc and SysReadSvc.
  • Run Antivirus Scans: Perform full antivirus scans with updated definitions across all endpoints and servers.
  • Reset Passwords: Reset passwords for any accounts suspected of exposure or compromise.
  • Monitor Network Traffic: Look for outbound connections to suspicious IP addresses (e.g., 81.177.32[.]12, 194.87.239[.]71) and domains associated with the attack.
  • Contact Kaspersky: If indicators of compromise are found, Kaspersky recommends contacting its ICS CERT team for further investigation support.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarePatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Chrome CVE-2023-151 Allows Remote Code Execution

Next Post

CVE-2024-23963: Apple Find My Vulnerability Exposes Real-Time User Locations

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TrueConf Server Flaws Let Attackers Push Malware via Updates
August 21, 2026
Critical Chrome CVE-2023-151 Allows Remote Code Execution
August 21, 2026
Critical Microsoft Entra ID RCE Vulnerability Exploited In The Wild
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us