Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participants
Description
The Head Mare APT group exploited two vulnerabilities in TrueConf video conferencing servers released since 2022 to deliver PhantomCore malware to conference participants. These vulnerabilities allowed attackers to execute arbitrary code, replace legitimate client installers with malicious versions, and deploy web shells. Infected installers deployed a backdoor granting attackers full control over infected systems. On Linux servers, additional backdoors used GitHub as a command and control channel. The vulnerabilities were patched in TrueConf server versions 5.3.9, 5.4.9, and 5.5.5 released in June 2026. Organizations with employees participating in TrueConf conferences may have been affected even without operating their own servers.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Head Mare advanced persistent threat group exploited two unpatched vulnerabilities in TrueConf video conferencing servers to conduct a supply chain attack. By leveraging these flaws, attackers executed arbitrary code on the servers, replaced legitimate TrueConf client installers with malicious versions containing the PhantomCore backdoor, and deployed web shells for persistent access. When conference participants downloaded the compromised client software, their systems became infected, allowing attackers full control. On Linux servers, the attackers installed additional backdoors that communicated via GitHub as a command and control channel. The affected TrueConf server versions include all releases since 2022 prior to 5.3.9. Official patches addressing these vulnerabilities were released in versions 5.3.9, 5.4.9, and 5.5.5 in June 2026.
Potential Impact
Successful exploitation results in full system compromise of conference participants who download the infected TrueConf client installers. Attackers gain persistent remote access via PhantomCore backdoors and web shells, enabling control over affected systems. Linux servers may have additional backdoors communicating through GitHub, increasing attacker persistence and stealth. Organizations using TrueConf servers prior to patched versions or whose employees participate in conferences hosted on compromised servers are at risk.
Defensive Guidance
TrueConf has released official patches in versions 5.3.9, 5.4.9, and 5.5.5 to address the exploited vulnerabilities. Organizations should upgrade their TrueConf servers to one of these patched versions immediately. Participants should obtain TrueConf client software only from trusted, updated sources. There is no indication that the vulnerabilities affect cloud-hosted services. No additional mitigation steps are specified by the vendor advisory.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://ics-cert.kaspersky.com/publications/reports/2026/08/12/head-mare-exploits-vulnerabilities-in-trueconf-server-to-deliver-phantomcore-malware"]
- Adversary
- Head Mare
- Pulse Id
- 6a87ffab05b89766cd6c1700
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip194.87.239.71 | — | |
ip194.87.93.153 | — | |
ip31.59.102.61 | — | |
ip38.244.205.244 | — | |
ip81.177.32.12 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0e4541c3153ec5ed01497f19cf4f63d0 | — | |
hash0e79996d9483d1e44fea32b0a48c2c19 | — | |
hash129462164a7d52e9ea8560b60f0412c5 | — | |
hash12d4e8f5295f2ef7e0f9bfc0f4830939 | — | |
hash2bb75c20e778eb5c416965bd4d4259b1 | — | |
hash43f435c3c437bc879a2d7d4634f43494 | — | |
hash489f43be558b2679284ceabed7adc4f3 | — | |
hash4d27b4eb1c5dbb3d8160f29b8119523e | — | |
hash748c9f8cb1065000616204935f96207f | — | |
hash7f267006cac10f341c356b62fe493527 | — | |
hash8fcc3e4ccbf1725d9989fb464abf3561 | — | |
hashaee9642b45b099cb7f3053b9b680b425 | — | |
hashb348642146ea34771e5785c5857950f5 | — | |
hashb3a6fee3307f1c26841fd5c603e2b013 | — | |
hashc3a2abe8756910f42582b04a44ea3514 | — | |
hashc5a460e4e68a088f6e51b2c6474642ec | — | |
hashdd1fd2b459b97b7d59375cb8383cd19a | — | |
hashec0bf4a2186a88874e9f26f07cfeb532 | — | |
hashee2861d5965e8730708cd1da8a93fa4c | — | |
hash7b9c37d82be5102e47a267e9f3c7c16b23bb1114 | — | |
hashac9f013ad20aab607264d7cfe69ad153a4224d4b | — | |
hashb7cea387205e16c9f43d750035e77735415dad34 | — | |
hashce1ae52bd60bf4a15a8d9aa597989b0d9df8ff3b | — | |
hashf9a692dadf9cc72352b979b1ecb80eb09ddf941a | — | |
hash0ed9306deabddaa587ad75d0775f7e63b27857a13adcc870dc9f8c92a9ddc6da | — | |
hash0fce4b732ce10c72093587e82ca9747a885430e366934ddc27e437443ff0cc0e | — | |
hash72029a4d4790784dd3029d13e73f57494dcb8f8187ca234b131e2b825bd84336 | — | |
hashb9e4052b310f9451eca9784a4a33bf5282d1bd07e3359eba9648be625e2e40dd | — | |
hashceea2f175eaa02919e8b5161c2ecf585de3e8b6d586bca8046eee2e3f4efa386 | — | |
hash4bbe23daa43583037420ff17b6c6d0844523037c | — | |
hash4333f52668996c0fa44c14fefba7fecc | — | |
hash1587b6b1949c83e5916cabe9b5882a2ce4d26902 | — | |
hash1a8fb0337a767126de8ba924be8b480fd57c30c9 | — | |
hash3e2908e1eebaa2aa52a154e8fb95059d91fe3a02 | — | |
hash6f6c9115f9464134cc881d0ef941de40dc09fb87 | — | |
hash76b90ba581a7792500b2ceea68d83bdb09d07093 | — | |
hashcf07cc0c04f1a5558e1976e0b0b2e80b89b43fcb | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainpenzadogshelter.site | — | |
domainurbanpixel.store | — | |
domainvks.gossopka.forum | — |
Threat ID: 6a880779acd9273b49cf3724
Added to database: 08/21/2026, 08:08:25 UTC
Last enriched: 09/28/2026, 01:49:11 UTC
Last updated: 10/04/2026, 08:55:38 UTC
Views: 148
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.