Head Mare Chains TrueConf Server Flaws to Drop PhantomCore and PhantomGraph

Red | Attack
Head Mare Chains TrueConf Server Flaws to Drop PhantomCore and PhantomGraph | TA2026228

Summary

Head Mare, first observed running this campaign in July 2026, is breaking into unpatched TrueConf video conferencing servers by chaining two vulnerabilities that let the group run code with SYSTEM privileges. The threat actor targets Instrumentation, Electronics, Transportation, Energy, IT, and Software Development organizations across Russia, running on Windows and Linux platforms. Once inside, Head Mare plants a web shell, swaps the legitimate TrueConf Client installer for a trojanized one carrying the PhantomCore backdoor, and deploys a second backdoor, PhantomGraph, that uses Microsoft OneDrive as its command-and-control channel. Users pull the poisoned installer as a routine "update," turning a trusted meeting tool into a delivery vehicle for credential theft and remote access.

Attack Details

#1 Unauthenticated Access via Port 4307

Head Mare is actively compromising unpatched TrueConf servers by connecting to TCP port 4307, a service that is open by default and reachable without any authentication. From there the group chains two vulnerabilities, tracked internally by Kaspersky as KLCERT-26-057 and KLCERT-26-058. The first lets the attacker push a malicious script and run it inside TrueConf's sandboxed environment, while the second breaks out of that sandbox to execute commands directly on the underlying operating system. The flaws affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older builds; the vendor patched them on June 18, 2026, and the attacks were uncovered the following month. Beyond exploiting the server directly, Head Mare also reaches victims through phishing, other public-facing web servers, and trusted contractors.

#2 Web Shell and Trojanized Installer

After escaping the sandbox, the attackers gain code execution as NT AUTHORITY\SYSTEM and overwrite the server's public\js\locale.php file with a web shell that gives them durable remote control. They use that web shell to map the IT environment, pull privileged access to the TrueConf database, and replace the legitimate TrueConf Client installer with a trojanized, unsigned build that carries the PhantomCore backdoor. PhantomCore keeps its foothold through a COM CLSID registry key so it loads automatically when the system starts. Alongside it, Head Mare deploys PhantomGraph, a backdoor deliberately split into two modules: SysExcSvc.dll fetches commands and returns their output through a Microsoft OneDrive account acting as command-and-control, while SysReadSvc.dll reads, executes, and stores the results. Both are registered as Windows services through a Base64-encoded PowerShell command, and the two-part design is meant to slip past EDR detection.

#3 Credential Harvesting and Reconnaissance

Working through PhantomGraph, the operators dumped the memory of the LSASS process to harvest credentials and ran quick reconnaissance with hostname and whoami to profile each compromised host. The blast radius reaches well beyond direct customers, because employees at organizations that do not even run TrueConf themselves can be infected simply by joining an online meeting on a compromised counterparty's server and downloading the poisoned installer as an update.

#4 Cloud-Blended Command and Control

For command-and-control and to move stolen data, PhantomGraph tunnels its traffic through a legitimate Microsoft OneDrive account, blending exfiltration into normal cloud activity, and the operators also stood up a reverse SSH tunnel for interactive access. Overlapping tools were detected utilizing GitHub as an alternative command-and-control channel, along with an ELF rootkit deployed on Linux hosts. Code similarities between PhantomGraph and PhantomCore link both clearly to Head Mare's arsenal. Multiple campaigns built on this toolkit are currently active against Russian organizations across several sectors.

Recommendations

01
Update TrueConf Server Immediately

Upgrade every TrueConf Server instance to version 5.3.9, 5.4.9, or 5.5.5, released on June 18, 2026, which closes the KLCERT-26-057 and KLCERT-26-058 vulnerabilities exploited in this attack.

02
Verify Client Installer Signatures

Confirm that any TrueConf Client distributed from your server carries a valid TrueConf digital signature, since the malicious installers seen in this campaign are unsigned. Authenticity can also be checked against the vendor's official download page.

03
Restrict Access to Port 4307/TCP

Limit exposure of TrueConf's default 4307/TCP service to trusted management networks, as attackers use this port to reach the server without authentication.

04
Watch for LSASS Access and SSH Tunnels

Alert on LSASS memory dumping, including access via comsvcs.dll, and on unexpected outbound SSH tunnels, both of which were used after compromise in this campaign.

05
Scrutinize Counterparty Meeting Installers

Treat any client downloaded when joining an external partner's TrueConf meeting as untrusted, because a compromised counterparty server can push infected installers to your staff.

Potential MITRE ATT&CK TTPs

Initial Access
T1190
Exploit Public-Facing Application — Head Mare reaches unpatched TrueConf servers directly over TCP port 4307.
Initial Access
T1199
Trusted Relationship — victims are infected via compromised counterparty TrueConf servers and trusted contractors.
Initial Access
T1566
Phishing — used as an alternate delivery path alongside direct server exploitation.
Execution
T1059
Command and Scripting InterpreterSub-techniques: T1059.001 — PowerShell · T1059.003 — Windows Command Shell
Persistence
T1505
Server Software ComponentSub-technique: T1505.003 — Web Shell
Persistence
T1543
Create or Modify System ProcessSub-technique: T1543.003 — Windows Service
Persistence
T1546
Event Triggered ExecutionSub-technique: T1546.015 — Component Object Model Hijacking
Privilege Escalation
T1068
Exploitation for Privilege Escalation — the sandbox-escape flaw grants SYSTEM-level code execution.
Defense Evasion
T1027
Obfuscated Files or Information — PhantomGraph's registration is delivered as Base64-encoded PowerShell.
Defense Evasion
T1036
Masquerading — the trojanized TrueConf Client installer is disguised as a legitimate routine update.
Credential Access
T1003
OS Credential DumpingSub-technique: T1003.001 — LSASS Memory
Discovery
T1082
System Information Discovery — performed via hostname after compromise.
Discovery
T1033
System Owner/User Discovery — performed via whoami after compromise.
Command and Control
T1102
Web ServiceSub-technique: T1102.002 — Bidirectional Communication (Microsoft OneDrive, GitHub)
Command and Control
T1572
Protocol Tunneling — a reverse SSH tunnel is used for interactive access.
Exfiltration
T1041
Exfiltration Over C2 Channel — stolen data is moved through the Microsoft OneDrive channel.

Indicators of Compromise (IOCs)

Type Value
MD5
4d27b4eb1c5dbb3d8160f29b8119523e748c9f8cb1065000616204935f96207fc5a460e4e68a088f6e51b2c6474642ec129462164a7d52e9ea8560b60f0412c5ec0bf4a2186a88874e9f26f07cfeb532b348642146ea34771e5785c5857950f5c915cb6c2aeb863ee8479238e16442170e79996d9483d1e44fea32b0a48c2c192bb75c20e778eb5c416965bd4d4259b1b3a6fee3307f1c26841fd5c603e2b0138fcc3e4ccbf1725d9989fb464abf3561489f43be558b2679284ceabed7adc4f3dd1fd2b459b97b7d59375cb8383cd19a0e4541c3153ec5ed01497f19cf4f63d012d4e8f5295f2ef7e0f9bfc0f48309397f267006cac10f341c356b62fe493527ee2861d5965e8730708cd1da8a93fa4cc3a2abe8756910f42582b04a44ea351443f435c3c437bc879a2d7d4634f43494aee9642b45b099cb7f3053b9b680b425
IPv4
81[.]177[.]32[.]12194[.]87[.]239[.]71194[.]87[.]93[.]15338[.]244[.]205[.]24431[.]59[.]102[.]61
Domains
penzadogshelter[.]sitetrendy-market[.]sitebright-deals[.]sitenova-stream[.]siterinomobile[.]inkurbanpixel[.]storeflexish[.]shopmedia-hub[.]todaycosmetic-deals[.]storevks[.]gossopka[.]forum
File Path
C:\Windows\System32\inetsrv\SysExcSvc.dllC:\Windows\System32\inetsrv\SysReadSvc.dllC:\Windows\System32\inetsrv\graphi-refresh.datC:\Windows\System32\inetsrv\share\input_*.txtC:\Windows\System32\inetsrv\share\output_*.txt%TEMP%\cmd_cmd_*.bat%LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll/etc/systemd/system/omicluster.service/etc/systemd/system/schedul2-bin.service/opt/acronis/bin/schedul2-bin/omi/bin/omicluster/usr/lib64/libzvbi-tchain.so.2/var/tmp/cx2
Registry Key
HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32
SHA256
0ED9306DEABDDAA587AD75D0775F7E63B27857A13ADCC870DC9F8C92A9DDC6DAE66BBB6C651B5AB839434B8E62F502169F35894E28DBE9F3275911582ECCD250B9E4052B310F9451ECA9784A4A33BF5282D1BD07E3359EBA9648BE625E2E40DD9464A414FD542F6E6B6245669EE947DFCBC9BA7C0641195C1E60E5C569B7269B23176FF5E92798B97341440A2A76F782729193C6FF65F71B8B6A315A2D507674171856ED2026C0099F7D84E06963D25B35627CFE45674BC82AB0F254A639613F3DB4B29804E36890B431D7C71796DF63A3DE367A2482FA588AEDE9E3C4FE6D3E2B1DD2B3C8508D5116BC3883FF619FD752EB662FD81CBA176CFE412E97A4BCBBA9D5F0E32DD7E0B1F7B0A1D901212F2BF9150C2E37EE60DCBBD53FC18D3C8DD272029A4D4790784DD3029D13E73F57494DCB8F8187CA234B131E2B825BD84336CEEA2F175EAA02919E8B5161C2ECF585DE3E8B6D586BCA8046EEE2E3F4EFA386EF8D99FDCD6E184F6DC5E0F57E1A78C6DF542505436FDE66D70BAAB994470B7B157103FF2306A8EF27F539307AA8CC3CDA392320770C0F434F00B02AEEB1DCAE4463687E07B1566323A84209972DE041031972F2A02DFCD6F1F0699C335EC5A621AB543D257FA6A71B5087F533BFCE54211D20D5FBA003F2FF7458F8FE6956400FCE4B732CE10C72093587E82CA9747A885430E366934DDC27E437443FF0CC0E0A8709032E890EE923D00A98C81DD188F1A8D0D3EA8DF5A65663AF5521C052CC91AA91ADB87674B5357CFA07A9B9C1C657EA052D081C6754C109CB64D187DBCF19262A37F9E5ED51A274B77BC73C3F9C2C2C7A2A567FA958ABF2D4FFEB426F12632F6D47E1CFBD4FABE2E85E9BA38EBA7DA33B0BADEC568935FA132E5A3A8160

References

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.