
KASPERSKY has revealed that the Head Mare group exploited two previously unknown flaws in TrueConf video‑conferencing servers to install the PhantomCore backdoor (according to its analysis).
The attackers used the zero‑day vulnerabilities to gain initial access through an open management port, then executed scripts that raised their privileges on the host (as detailed by SecurityOnline).
With elevated rights they replaced the legitimate TrueConf client installer with a trojanised version that dropped PhantomCore, allowing persistent remote control of any machine that connected to the compromised server.
Kaspersky first observed the activity in July 2026 and tracked it from 11 August to 17 August 2026, noting that the campaign primarily targeted Russian organisations across energy, finance and government sectors.
The security firm has published indicators of compromise, including specific file hashes and registry keys linked to PhantomCore, and confirmed that the exploited flaws have since been patched in the latest TrueConf releases.
Administrators should immediately update their TrueConf servers to the patched version, verify the digital signature of any client installer before deployment and monitor network traffic for connections to the command‑and‑control addresses associated with the hashes provided by Kaspersky.