< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-10T17:03:41+05:30

Head Mare Exploits TrueConf Server Vulnerabilities to Deploy PhantomCore Backdoor

Threat group Head Mare exploited unpatched TrueConf server vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to replace client installers with PhantomCore backdoor and RAT, impacting Russian enterprises. The attack chain involved privilege escalation, web shell deployment, and modular malware components, with vulnerabilities subsequently patched in June 2026.

The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.

Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.

The activity involves exploiting a vulnerability chain

Read original article

*** END OF TRANSMISSION ***