securelist.com 8/11/2026, 12:32:26 PM · external

Kaspersky uncovers Head Mare APT exploiting TrueConf video flaws

Kaspersky uncovers Head Mare APT exploiting TrueConf video flaws
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

IN July 2026, Kaspersky reported a new attack by the Head Mare group, deemed an Advanced Persistent Threat (APT) due to their sophisticated techniques. The attackers exploited multiple vulnerabilities in the TrueConf video conferencing server, bypassing security measures to install the PhantomCore malware. The attack involved unauthorized access to the server using an open port and executing malicious scripts that allowed them to gain elevated privileges.

They replaced legitimate client software with infected versions to spread malware further. Key vulnerabilities have since been patched. Kaspersky's solutions successfully detected the malicious activity and identified multiple indicators of compromise associated with the attack, including specific file hashes and registry modifications.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline