Head Mare has been exploiting unpatched TrueConf server vulnerabilities to replace legitimate client installers with trojanized versions that deliver the PhantomCore and PhantomGraph backdoors. Kaspersky says the campaign targets Russian organizations and can impact users even through compromised third-party TrueConf servers, enabling credential theft, reconnaissance, and persistent remote access. #HeadMare #TrueConf #PhantomCore #PhantomGraph
Keypoints
- Head Mare abused TrueConf server flaws to gain unauthorized access.
- The attacker replaced legitimate installers with malicious versions carrying PhantomCore.
- PhantomGraph used OneDrive for command control and credential theft.
- The campaign affected Russian organizations across multiple sectors.
- TrueConf fixed the vulnerable versions in updates released on June 18.