Head Mare Exploits Vulnerabilities In Trueconf Server To Deliver Phantomcore Malware
While investigating an attack on Russian organizations, Kaspersky experts discovered that client installers for the TrueConf video conferencing and corporate communications platform were installing PhantomCore malware in addition to their standard functionality. PhantomCore malware is typically associated with the activity of the Head Mare APT group. The malicious installers were downloaded from a TrueConf server belonging to the attacked organization.
Research into the compromised server revealed that attackers use a combination of two vulnerabilities (assigned internal Kaspersky identifiers KLCERT-26-057 and KLCERT-26-058 ) to execute arbitrary code. This enables them to replace one of the TrueConf server files with their own web shell. This web shell is later used to gather information the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database, and replace the legitimate client installers mentioned earlier.
On *nix servers running TrueConf, the attackers install a backdoor that hides its files and, by intercepting TrueConf network functions, listens for commands sent from the attackers via the TrueConf protocol. Furthermore, on *nix systems, the attackers install a backdoor that uses GitHub as a command and control channel.
The manufacturer addressed the vulnerabilities used by the attackers in the latest TrueConf server update (versions 5.3.9, 5.4.9, and 5.5.5), released on June 18, 2026 . We are currently coordinating with the vendor’s representatives to notify users and mitigate the consequences of the attack. The vendor continues to notify TrueConf system administrators of the need for immediate updates as soon as the relevant versions are released.
This document is intended to alert both TrueConf server owners, as well as organizations whose employees have participated in video conferences using TrueConf and may have downloaded malware as part of the client application installation packages.
To reduce the risk of security incidents, we recommend taking the measures outlined in this document as soon as possible.
For more information, please us at [email protected] .
An unauthorized attacker can connect to TrueConf server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5, as well as earlier versions (our internal analysis showed that all TrueConf server versions released since 2022 are vulnerable) via port 4307/TCP (open by default, according to TrueConf documentation) and execute a malicious script on the server by calling an undocumented function. The internal identifier KLCERT-26-057 has been assigned to track this vulnerability.
The uploaded malicious script is executed in an isolated environment, where potentially hazardous libraries (io, os, etc.) are unavailable. However, attackers can exploit another vulnerability (assigned internal Kaspersky identifier KLCERT-26-058 ) to execute arbitrary code on the server with NT AUTHORITY\SYSTEM privileges. This enables them to replace the file C:/Program Files/TrueConf Server/httpconf/site/public/js/locale.php with a malicious web shell program, as well as delete records from the TrueConf event logs related to the exploit’s operation.
Attackers use the web shell to install a backdoor-type malicious program on the server that consists of two components:
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc . The attackers install this malware as a backup command and control channel because all subsequent actions are carried out by remotely running PowerShell scripts via a web shell. A detailed analysis of the malware and the attackers’ actions will be presented on the Kaspersky Threat Intelligence Portal in a separate report on this series of attacks.
Most importantly, during the attack, the attackers replace the TrueConf client distribution file located at C:\Program Files\TrueConf Server\ClientInstFiles\trueconf_windows_client_x64.exe . After that, all conference participants with x64-based systems receive a message stating that they need to download a new version of the TrueConf client.
Important! Even if your organization does not use a TrueConf server, your employees may connect to compromised TrueConf servers of contractors to participate in online meetings and download infected installation packages.
According to the research, after launching on a workstation, the infected installer deploys the TrueConf client on the system, but also unpacks the PhantomCore malware to the path %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll .
This malware enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system. To automatically launch the malware after system startup, a registry key is created: HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 , with the value pointing to the malicious executable file.
A detailed description of the malware will also be presented in a report on the analyzed series of attacks.
Note: The indicators provided in this section were valid and up-to-date at the time of publication.
File hashes (MD5) 4d27b4eb1c5dbb3d8160f29b8119523e – web shell locale.php 748c9f8cb1065000616204935f96207f – malicious installer trueconf_windows_update.exe c5a460e4e68a088f6e51b2c6474642ec – PhantomCore backdoor 129462164a7d52e9ea8560b60f0412c5 – doc.txt ec0bf4a2186a88874e9f26f07cfeb532 – usocacheddata.txt b348642146ea34771e5785c5857950f5 c915cb6c2aeb863ee8479238e1644217 – doc.txt 0e79996d9483d1e44fea32b0a48c2c19 – doc.txt 2bb75c20e778eb5c416965bd4d4259b1 – trueconf_windows_client_x64_[redacted].exe b3a6fee3307f1c26841fd5c603e2b013 – usocacheddata.txt 8fcc3e4ccbf1725d9989fb464abf3561 – usocacheddata.txt 489f43be558b2679284ceabed7adc4f3 – PhantomGraph backdoor 0e4541c3153ec5ed01497f19cf4f63d0 – PhantomGraph backdoor 12d4e8f5295f2ef7e0f9bfc0f4830939 – PhantomGraph backdoor 7f267006cac10f341c356b62fe493527 – PhantomGraph backdoor ee2861d5965e8730708cd1da8a93fa4c – PhantomGraph backdoor dd1fd2b459b97b7d59375cb8383cd19a – PhantomGraph backdoor 4333f52668996c0fa44c14fefba7fecc – Linux backdoor c3a2abe8756910f42582b04a44ea3514 – Linux backdoor 43f435c3c437bc879a2d7d4634f43494 – Linux backdoor aee9642b45b099cb7f3053b9b680b425 – rootkit/backdoor
File paths C:\Windows\System32\inetsrv\SysExcSvc.dll C:\Windows\System32\inetsrv\SysReadSvc.dll C:\Windows\System32\inetsrv\graphi-refresh.dat C:\Windows\System32\inetsrv\ \input_*.txt C:\Windows\System32\inetsrv\ \output_*.txt %TEMP%\cmd_cmd_*.bat %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll /etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service /opt/acronis/bin/schedul2-bin /omi/bin/omicluster /usr/lib64/libzvbi-tchain.so.2 /var/tmp/cx2
IP addresses and domain names 81.177.32[.]12 194.87.239[.]71 194.87.93[.]153 38.244.205[.]244 31.59.102[.]61 penzadogshelter[.]site trendy-market[.]site bright-deals[.]site nova-stream[.]site rinomobile[.]ink urbanpixel[.]store flexish[.]shop media-hub[.]today cosmetic-deals[.]store vks.gossopka[.]forum
Windows service names SysExcSvc SysReadSvc
Registry keys HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32
Security solutions verdicts Backdoor.PHP.WebShell.abi Backdoor.Win64.PhantomCore.dt Trojan.Win64.Agent.smgvnc HEUR:Backdoor.Win64.PhantomCore.gen HEUR:Backdoor.Linux.Agent.fb Trojan.Win64.PhantomGraph.gen Trojan.Win64.Agent.smgvnb UDS:Backdoor.Win64.PhantomCore.a
YARA rules import "pe"
rule apt_HeadMare_PhantomCore { meta: description = "Rule to detect PhantomCore used by HeadMare" author = "Kaspersky" copyright = "Kaspersky" version = "1.0" last_modified = "2026-08-02" hash = "c5a460e4e68a088f6e51b2c6474642ec"
strings: $a1 = "lying.dll" ascii $a2 = { 2D 7F 95 4C 2D F4 51 58 } $a3 = { 4F 81 67 F7 7E 7B 05 14 }
condition: (uint16(0) == 0x5A4D) and (filesize > 4MB) and (filesize 20MB) and (all of them) and (pe.number_of_signatures == 0) }
rule apt_HeadMare_PhantomCore_exchange { meta: description = "Rule to detect PhantomCore exchange module used by HeadMare" author = "Kaspersky" copyright = "Kaspersky" version = "1.0" last_modified = "2026-08-02" hash = "489f43be558b2679284ceabed7adc4f3"
strings: $a1 = "graphi_exchange.dll" ascii $a2 = "graphi-client/1.0" ascii
$b1 = " ascii $b2 = ":/children?$select=name,id&$top=200" ascii $b3 = "offline_access Files.ReadWrite" ascii $b4 = "GRAPHI_INSECURE" ascii $b5 = "\"@microsoft.graph.conflictBehavior\":\"replace\"}" ascii $b6 = " ascii
condition: (uint16(0) == 0x5A4D) and (any of ($a*)) and (3 of ($b*)) }
rule apt_HeadMare_PhantomCore_executor { meta: description = "Rule to detect PhantomCore executor module used by HeadMare" author = "Kaspersky" copyright = "Kaspersky" version = "1.0" last_modified = "2026-08-02" hash = "dd1fd2b459b97b7d59375cb8383cd19a"
strings: $a1 = "graphi_reader.dll" ascii $a2 = "^input_(.+)\\.txt$" ascii
$b1 = "output_" ascii $b2 = "cmd_cmd_" ascii $b3 = "cmd /c \"\"" ascii $b4 = "error: failed to start cmd process" ascii $b5 = " " ascii $b6 = "SysReadSvc" ascii
condition: (uint16(0) == 0x5A4D) and (filesize 5000000) and (filesize < 10000000) and (4 of them) }
Kaspersky ICS CERT Team
Kaspersky Threat Research
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
