TrueConf Breach Exposes Client Installers to Trojanized Backdoors

www.news4hackers.com-trueconf-breach-exposes-client-installers-to-trojanized-backdoors-trueconf-breach-exposes-client-installers-to-trojanized-backdoors

Experts reveal how a cyber threat group exploited unpatched vulnerabilities in TrueConf servers to distribute malicious installers with backdoors.

Cyber Threat Group Head Mare

A cyber threat group known as Head Mare has exploited unpatched vulnerabilities in TrueConf video conferencing servers to distribute malicious client installers containing backdoors. The attack involved compromising servers to replace legitimate software with modified versions that establish persistent remote access.

Exploited Vulnerabilities

Researchers at Kaspersky identified the breach in July. The group exploited two vulnerabilities, designated KLCERT-26-057 and KLCERT-26-058, to gain unauthorized access to TrueConf servers. Attackers used TCP port 4307, which is enabled by default, to connect to the servers without authentication.

The first vulnerability enabled execution of a malicious script within the platform’s isolated environment, while the second allowed the attackers to escape the sandbox and execute commands on the underlying operating system.

Privilege Escalation and Web Shell

Once inside, the threat actors escalated privileges to NT AUTHORITY\\SYSTEM, the highest level of access on Windows systems. They replaced the \\public\\js\\locale.php file with a web shell, granting persistent remote control over the compromised server.

Malicious Installer Distribution

This web shell was used to extract sensitive data, access the TrueConf database, and replace the official client installer hosted on the server with a malicious version containing the PhantomCore backdoor. When users connected to the compromised server, they received a modified installer that lacked digital signatures. This allowed the backdoor to be deployed silently.

Additional Backdoor Deployment

Additionally, the attackers deployed PhantomGraph, a separate backdoor consisting of two DLL files (SysExcSvc.dll and SysReadSvc.dll). This component communicated with the attackers via a Microsoft OneDrive account, executing commands and returning results.

Observed Activities and Targeting

Observed activities via PhantomGraph included memory dumping of the Local Security Authority Subsystem Service (LSASS) to steal credentials, reconnaissance commands like hostname and whoami, and the establishment of a reverse SSH tunnel. Kaspersky noted that Head Mare is actively targeting Russian organizations across multiple sectors, including instrumentation, electronics, transportation, energy, IT, and software development.

Patches and Recommendations

The vulnerabilities exploited by the group affect TrueConf Server versions 5.3.x (before 5.3.9), 5.4.x (before 5.4.9), 5.5.x (before 5.5.5), and earlier. The vendor released patches for these issues in versions 5.3.9, 5.4.9, and 5.5.5 on June 18. Organizations using TrueConf are advised to apply the latest patches immediately and monitor for signs of compromise, such as unauthorized changes to server files or unexpected network activity.

Related Campaigns and Trends

In April 2026, CheckPoint Research reported a separate campaign, Operation True Chaos, targeting a zero-day flaw (CVE-2026-3502) in TrueConf. This attack involved trojanized client updates and was linked to Chinese threat actors associated with the Havoc implant. The breach highlights the risks of unpatched systems and the importance of securing internal infrastructure.

Attackers often leverage weakly configured services and outdated software to gain initial access. Head Mare’s tactics align with broader trends in cyber espionage, where threat actors combine multiple techniques to maintain long-term access and exfiltrate sensitive data. The use of web shells and custom backdoors underscores the need for continuous threat hunting and robust endpoint detection capabilities.



About Author

en_USEnglish