Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US offers $1bn to Colombia on new right-wing president’s first day of office

    August 8, 2026

    The Kindle Scribe Colorsoft is a lot of fun, but it’s not a must-have

    August 8, 2026

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US offers $1bn to Colombia on new right-wing president’s first day of office
    • The Kindle Scribe Colorsoft is a lot of fun, but it’s not a must-have
    • Critical Vulnerabilities Patched With Chrome 151 Update
    • T. Rowe Price defends memecoin exposure in new crypto ETF, calling it a blockchain ‘stress test’
    • From small cats to pangolins: Detection dogs help track elusive species
    • UAE says Iran targeted ADNOC tanker in Strait of Hormuz, no casualties | US-Israel war on Iran News
    • Senate passes Russia sanctions bill
    • Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers breach TrueConf to trojanize client installers with backdoors

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.

    The exploited vulnerabilities allowed the attacker to execute arbitrary code with the highest level of privileges and deploy the PhantomCore and PhantomGraph backdoors.

    TrueConf is a video conferencing tool widely used in Russia, especially in the enterprise and government sectors, as a secure, on-premise alternative to Western tools such as Zoom and Microsoft Teams.

    image

    Researchers at cybersecurity company Kaspersky discovered the attack in July. They found that Head Mare hackers used TCP port 4307, which is open by default, to connect to the target TrueConf server without authentication.

    They leveraged a vulnerability internally tracked by Kaspersky as KLCERT-26-057 to execute a malicious script within TrueConf’s isolated environment, and KLCERT-26-058 to escape the sandbox and run commands on the underlying operating system.

    The attacker then increased their privileges to NT AUTHORITYSYSTEM, and replaced the ‘publicjslocale.php’ file with a web shell that gave them persistent remote access to the compromised server.

    Kaspersky reports that Head Mare uses a web shell to collect sensitive information from the victim’s environment, access the TrueConf database, and replace the legitimate TrueConf Client installer hosted on the server with a malicious version that contains the PhantomCore backdoor.

    When members of the organization connect to the local TrueConf server, they receive a trojanized, non-digitally signed client installer as an update.

    “Even if your organization does not use the TrueConf server, employees of the organization can connect to compromised counterparty TrueConf servers to participate in online meetings and download infected installation packages,” Kaspersky warns.

    Additionally, Head Mare deploys PhantomGraph, a separate backdoor consisting of two DLL files (SysExcSvc.dll and SysReadSvc.dll) that accept commands via a Microsoft OneDrive account, execute them, and return the results.

    Observed attacker activity through PhantomGraph included dumping the memory of the Local Security Authority Subsystem Service (LSASS) process to exfiltrate credentials.

    The malware also runs commands for reconnaissance activity, such as hostname and whoami, and starts a reverse SSH tunnel.

    Kaspersky says it is currently observing multiple active Head Mare campaigns targeting Russian organizations in various sectors: instrumentation, electronics, transportation, energy, IT, and software development.

    According to the researchers, the threat actor is using several initial access methods that include phishing, exploiting public-facing web servers, and access via contractors.

    TrueConf vulnerabilities

    The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.

    The vendor fixed them in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18.

    In April 2026, CheckPoint Research reported that hackers were targeting a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502, compromising users via trojanized client updates.

    CheckPoint named the campaign ‘Operation True Chaos,’ and tentatively attributed it to Chinese threat actors behind the Havoc implant, which was used in these attacks.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Backdoors breach client hackers installers trojanize TrueConf
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Vulnerabilities Patched With Chrome 151 Update

    Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

    Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride

    Swiss government SharePoint breach compromised 200 accounts

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US offers $1bn to Colombia on new right-wing president’s first day of office

    August 8, 2026

    The Kindle Scribe Colorsoft is a lot of fun, but it’s not a must-have

    August 8, 2026

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 8, 2026

    T. Rowe Price defends memecoin exposure in new crypto ETF, calling it a blockchain ‘stress test’

    August 8, 2026
    Latest Posts

    With Hopes High for New H.I.V. Prevention Pill, Merck Takes Steps to Ensure Access

    July 24, 2026

    Trump to speak at rescheduled White House Correspondents’ Dinner following failed April shooting

    July 24, 2026

    When is an apology not an apology? When it comes from an AI boss with an out-of-control chatbot | Marina Hyde

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US offers $1bn to Colombia on new right-wing president’s first day of office

    August 8, 2026

    The Kindle Scribe Colorsoft is a lot of fun, but it’s not a must-have

    August 8, 2026

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.