IN July 2026, Kaspersky reported a new attack by the Head Mare group, deemed an Advanced Persistent Threat (APT) due to their sophisticated techniques. The attackers exploited multiple vulnerabilities in the TrueConf video conferencing server, bypassing security measures to install the PhantomCore malware. The attack involved unauthorized access to the server using an open port and executing malicious scripts that allowed them to gain elevated privileges.
They replaced legitimate client software with infected versions to spread malware further. Key vulnerabilities have since been patched. Kaspersky's solutions successfully detected the malicious activity and identified multiple indicators of compromise associated with the attack, including specific file hashes and registry modifications.