Head Mare APT Group Exploits TrueConf Vulnerabilities to Deploy PhantomCore Malware in Sophisticated Attack

Published:

Head Mare APT Group Exploits TrueConf Vulnerabilities to Deploy PhantomCore Malware in Sophisticated Attack

In July 2026, cybersecurity experts from Kaspersky identified a sophisticated cyberattack attributed to the Head Mare group. Initially categorized as hacktivists, this group has now been reclassified as an Advanced Persistent Threat (APT) due to their advanced tactics, techniques, and procedures (TTPs). The recent campaign specifically targeted vulnerabilities within the TrueConf video conferencing server, leading to the deployment of the PhantomCore malware.

The attackers exploited two newly identified vulnerabilities, designated as KLCERT-26-057 and KLCERT-26-058. These vulnerabilities enabled the execution of arbitrary code with elevated privileges on compromised systems, marking a significant escalation in their operational capabilities.

Attack Methodology

The attack unfolds in several distinct stages:

  1. Unauthorized Access: The attackers gain access to the TrueConf server through port 4307/TCP, which is open by default. The affected versions include 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5.

  2. Malicious Script Execution: Once connected, the attackers invoke a server function that transmits a malicious script, exploiting the KLCERT-26-057 vulnerability.

  3. Isolation Bypass: The script executes within an isolated environment on the TrueConf server, which typically restricts access to operating system functions. To escape this environment, the attackers leverage the KLCERT-26-058 vulnerability, allowing them to execute commands in the operating system context.

  4. Web Shell Deployment: With elevated privileges, the attackers replace the legitimate file …publicjslocale.php with a web shell, granting them remote control over the server.

Malware Deployment and Persistence

The web shell enables a range of malicious activities, including:

  • Infrastructure Reconnaissance: Gathering information about the IT infrastructure.
  • Database Access: Gaining privileged access to the TrueConf database.
  • Installer Compromise: Replacing the original TrueConf Client installer with a compromised version that includes the PhantomCore backdoor.

To ensure the malware executes upon system boot, the attackers create a registry key at HKEY_CURRENT_USERSoftwareClassesCLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}InprocServer32, which points to the malicious executable.

Additionally, the attackers deploy a secondary backdoor known as PhantomGraph, which consists of two modules:

  • SysExcSvc.dll: This module receives commands from the attackers and sends back execution results, utilizing a Microsoft OneDrive account as its command-and-control (C2) server.
  • SysReadSvc.dll: This module executes the commands received from SysExcSvc.dll and saves the results.

To maintain persistence, the attackers execute a Base64-encoded PowerShell command that installs both modules as Windows services, complicating detection efforts by endpoint detection and response (EDR) tools.

Detection and Recommendations

Kaspersky’s security solutions effectively detect the malicious activities associated with this attack. The malware is identified by various detection names, including:

  • Backdoor.PHP.WebShell.abi
  • Backdoor.Win64.PhantomCore.dt
  • Trojan.Win64.Agent.smgvnc
  • Trojan.Win64.Agent.smgvnb
  • HEUR:Backdoor.Win64.PhantomCore.gen

Organizations utilizing TrueConf software are strongly advised to update to the latest server versions (5.3.9, 5.4.9, and 5.5.5) as per vendor recommendations. It is also crucial to verify that client distributions downloaded from the TrueConf server are digitally signed and have not been tampered with, as the malicious versions detected lacked valid signatures.

Organizations that do not directly use TrueConf servers should remain vigilant, as employees may connect to compromised servers belonging to business partners during online meetings, potentially downloading infected installation packages.

For a detailed analysis of the attack mechanism and exploited vulnerabilities, refer to the comprehensive report on the Kaspersky ICS CERT website.

Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.

Published on 2026-08-15 15:20:00 • By the Editorial Desk

Share post:

[tds_leads title_text="Subscribe" input_placeholder="Email address" btn_horiz_align="content-horiz-center" pp_checkbox="yes" pp_msg="SSd2ZSUyMHJlYWQlMjBhbmQlMjBhY2NlcHQlMjB0aGUlMjAlM0NhJTIwaHJlZiUzRCUyMiUyMyUyMiUzRVByaXZhY3klMjBQb2xpY3klM0MlMkZhJTNFLg==" f_title_font_family="653" f_title_font_size="eyJhbGwiOiIyNCIsInBvcnRyYWl0IjoiMjAiLCJsYW5kc2NhcGUiOiIyMiJ9" f_title_font_line_height="1" f_title_font_weight="700" f_title_font_spacing="-1" msg_composer="success" display="column" gap="10" input_padd="eyJhbGwiOiIxNXB4IDEwcHgiLCJsYW5kc2NhcGUiOiIxMnB4IDhweCIsInBvcnRyYWl0IjoiMTBweCA2cHgifQ==" input_border="1" btn_text="I want in" btn_tdicon="tdc-font-tdmp tdc-font-tdmp-arrow-right" btn_icon_size="eyJhbGwiOiIxOSIsImxhbmRzY2FwZSI6IjE3IiwicG9ydHJhaXQiOiIxNSJ9" btn_icon_space="eyJhbGwiOiI1IiwicG9ydHJhaXQiOiIzIn0=" btn_radius="3" input_radius="3" f_msg_font_family="653" f_msg_font_size="eyJhbGwiOiIxMyIsInBvcnRyYWl0IjoiMTIifQ==" f_msg_font_weight="600" f_msg_font_line_height="1.4" f_input_font_family="653" f_input_font_size="eyJhbGwiOiIxNCIsImxhbmRzY2FwZSI6IjEzIiwicG9ydHJhaXQiOiIxMiJ9" f_input_font_line_height="1.2" f_btn_font_family="653" f_input_font_weight="500" f_btn_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_btn_font_line_height="1.2" f_btn_font_weight="700" f_pp_font_family="653" f_pp_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_pp_font_line_height="1.2" pp_check_color="#000000" pp_check_color_a="#ec3535" pp_check_color_a_h="#c11f1f" f_btn_font_transform="uppercase" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjQwIiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGUiOnsibWFyZ2luLWJvdHRvbSI6IjM1IiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGVfbWF4X3dpZHRoIjoxMTQwLCJsYW5kc2NhcGVfbWluX3dpZHRoIjoxMDE5LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" msg_succ_radius="2" btn_bg="#ec3535" btn_bg_h="#c11f1f" title_space="eyJwb3J0cmFpdCI6IjEyIiwibGFuZHNjYXBlIjoiMTQiLCJhbGwiOiIxOCJ9" msg_space="eyJsYW5kc2NhcGUiOiIwIDAgMTJweCJ9" btn_padd="eyJsYW5kc2NhcGUiOiIxMiIsInBvcnRyYWl0IjoiMTBweCJ9" msg_padd="eyJwb3J0cmFpdCI6IjZweCAxMHB4In0="]

Popular

More like this
Related

Microsoft plans to use biomimicry to reduce the environmental impact of its data centers

Microsoft has announced plans to implement biomimicry in its data centers to mitigate their environmental impact. This initiative aims to integrate these facilities more harmoniously into local ecosystems, as reported by The Verge. The company intends to enhance biodiversity and…

Tokyo court grants legal protection to human voices in AI clone case involving Kenjiro Tsuda

A Tokyo court has granted legal protection to human voices in a significant ruling involving Kenjiro Tsuda, a prominent anime voice actor known for his distinctive baritone. The decision, reported by Emirates 247, marks the first legal acknowledgment of an…

Bank of England governor calls for rigorous AI testing before regulation

The Governor of the Bank of England, Andrew Bailey, has emphasised the need for "rigorous" testing of artificial intelligence (AI) before implementing regulations. In his inaugural article for Substack, Bailey stated that while the risks associated with AI are "real…

Eleven Emirati AI experts engage with Canadian institutions to enhance responsible AI applications

Eleven Emirati artificial intelligence experts from the National Experts Programme’s Artificial Intelligence track (NEP-AI) are currently engaging with leading Canadian institutions to explore the translation of advanced AI research into responsible applications. This international study visit, which commenced on Monday…