TrueConf Server Flaws Expose Client Installers To Backdoors
BleepingComputer reported that unpatched TrueConf servers are being abused to deliver backdoored client installers, with Kaspersky linking the activity to Head Mare and fixed server branches now available.

BleepingComputer reported that unpatched TrueConf video conferencing servers are being used to distribute backdoored client installers, exposing a trusted collaboration update path to supply-chain abuse.
The risk extends beyond the organization operating the vulnerable server.
Employees may also encounter the infected package when they join meetings hosted by a compromised counterparty and download a TrueConf client from that server.
Server Flaws Expose The Installer Path
Kaspersky researchers found the activity in July and tied it to the Head Mare hacktivist group.
Their analysis says Head Mare reached servers through the default TCP port 4307, then used KLCERT-26-057 for script execution inside TrueConf's isolated environment and KLCERT-26-058 for sandbox escape, operating-system commands and NT AUTHORITY\SYSTEM privileges.
With elevated access, the intruder replaced a public JavaScript locale file with a web shell.
That foothold enabled remote access to the server, collection of sensitive information, access to the product database and replacement of the hosted client installer with a version carrying the PhantomCore backdoor.
PhantomGraph Uses OneDrive For Commands
The same activity also deployed PhantomGraph, a separate backdoor made of two DLL files.
The malware accepted commands through a Microsoft OneDrive account, executed them in the victim environment and returned the results through the same channel.
Observed activity included LSASS memory dumping for credential theft, basic reconnaissance commands such as hostname and whoami, and creation of a reverse SSH tunnel.
Kaspersky is tracking multiple active Head Mare campaigns against Russian organizations in instrumentation, electronics, transportation, energy, IT and software development.
The researchers also identified several access routes beyond the video-conferencing server chain, including phishing, public-facing web server exploitation and contractor access.
That mix makes the compromised installer one element of a wider intrusion pattern.
Patches Define The Immediate Control
The exploited flaws affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5 and older versions.
Fixed branches are available for the affected TrueConf Server lines.
The practical control list is to update exposed servers, verify hosted client installers and investigate unexpected unsigned client packages.
A separate earlier TrueConf update-abuse case leaves the installer path as a recurring server integrity check rather than a one-off incident detail.




















