News
MARKET SIGNAL:

TrueConf Server Flaws Expose Client Installers To Backdoors

Newsroom brief

BleepingComputer reported that unpatched TrueConf servers are being abused to deliver backdoored client installers, with Kaspersky linking the activity to Head Mare and fixed server branches now available.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: BleepingComputer
TrueConf Server Flaws Expose Client Installers To Backdoors
Image source: BleepingComputer

BleepingComputer reported that unpatched TrueConf video conferencing servers are being used to distribute backdoored client installers, exposing a trusted collaboration update path to supply-chain abuse.

The risk extends beyond the organization operating the vulnerable server.

Employees may also encounter the infected package when they join meetings hosted by a compromised counterparty and download a TrueConf client from that server.

Server Flaws Expose The Installer Path

Kaspersky researchers found the activity in July and tied it to the Head Mare hacktivist group.

Their analysis says Head Mare reached servers through the default TCP port 4307, then used KLCERT-26-057 for script execution inside TrueConf's isolated environment and KLCERT-26-058 for sandbox escape, operating-system commands and NT AUTHORITY\SYSTEM privileges.

With elevated access, the intruder replaced a public JavaScript locale file with a web shell.

That foothold enabled remote access to the server, collection of sensitive information, access to the product database and replacement of the hosted client installer with a version carrying the PhantomCore backdoor.

PhantomGraph Uses OneDrive For Commands

The same activity also deployed PhantomGraph, a separate backdoor made of two DLL files.

The malware accepted commands through a Microsoft OneDrive account, executed them in the victim environment and returned the results through the same channel.

Observed activity included LSASS memory dumping for credential theft, basic reconnaissance commands such as hostname and whoami, and creation of a reverse SSH tunnel.

Kaspersky is tracking multiple active Head Mare campaigns against Russian organizations in instrumentation, electronics, transportation, energy, IT and software development.

The researchers also identified several access routes beyond the video-conferencing server chain, including phishing, public-facing web server exploitation and contractor access.

That mix makes the compromised installer one element of a wider intrusion pattern.

Patches Define The Immediate Control

The exploited flaws affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5 and older versions.

Fixed branches are available for the affected TrueConf Server lines.

The practical control list is to update exposed servers, verify hosted client installers and investigate unexpected unsigned client packages.

A separate earlier TrueConf update-abuse case leaves the installer path as a recurring server integrity check rather than a one-off incident detail.

Share this article
inXf

Related articles

More
Target-Locked Malware Narrows Central Asia Cyber Espionage Risk
Cybersecurity

Target-Locked Malware Narrows Central Asia Cyber Espionage Risk

Backend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare and research bodies in Central Asia and Syria.

SourTrade Malvertising Makes Browsers Assemble Windows Malware
Cybersecurity

SourTrade Malvertising Makes Browsers Assemble Windows Malware

The Hacker News reported that Confiant analysed SourTrade, a malvertising campaign that uses fake trading pages and browser-side assembly to vary Windows malware files for retail trading and crypto targets.

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain
Cybersecurity

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain

DeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.

Rails Fixes Critical Active Storage File-Read Vulnerability
Cybersecurity

Rails Fixes Critical Active Storage File-Read Vulnerability

BleepingComputer reported that Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw tied to libvips image processing and possible file exposure in vulnerable applications.

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs
Cybersecurity

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs

BleepingComputer reported that Google attributed 1,072 Chrome security bug fixes to Chrome 149 and Chrome 150, while faster patch delivery remains part of the browser security plan.

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact
Cybersecurity

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact

CyberScoop reported that Anthropic used Claude Mythos Preview to find weaknesses in HAWK and a reduced AES test, while Anthropic stressed that current software remains unaffected.

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Cybersecurity

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools
Cybersecurity

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools

BleepingComputer reported that Pillar Security reproduced sandbox-escape paths in Cursor, OpenAI Codex, Gemini CLI and Google Antigravity, shifting attention from agent containment to trusted developer tools around the workspace.

Keep Reading

More Stories

Latest
USTC Quantum Memories Reach 420km Fibre EntanglementTelco & ConnectivityAug 9, 2026USTC Quantum Memories Reach 420km Fibre EntanglementUSTC researchers entangled two quantum memories across a 420km optical-fibre link, using rubidium atom memories, telecom-compatible wavelengths and stabilisation to move quantum-network research beyond metropolitan-scale demonstrations.Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaCloud & Data CentersAug 8, 2026Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaData Center Dynamics reported that Indosat, Ooredoo Group, Nokia and Nvidia launched Zankore by Indosat with a plan for up to 1GW of AI data centre capacity in Indonesia.Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightAIAug 8, 2026Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightCNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.China Opens Security Review Of Palo Alto Networks ProductsCybersecurityAug 7, 2026China Opens Security Review Of Palo Alto Networks ProductsChina's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.