Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

0
Medium
Published: 08/11/2026 (08/11/2026, 15:24:17 UTC)
Source: AlienVault OTX General

Description

The Head Mare APT group exploited unpatched vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers gained unauthorized access via port 4307/TCP, executing arbitrary code with SYSTEM privileges. They replaced legitimate client installers with infected versions and deployed a web shell for persistence. PhantomGraph used Microsoft OneDrive for command-and-control. Affected TrueConf versions include 5.3.x through 5.3.9, 5.4.x through 5.4.9, and 5.5.x through 5.5.5. Multiple Russian organizations across various industries were targeted. The vulnerabilities were patched in June 2026.

Affected software

Affected versions
>=5.3.0 <=5.3.9>=5.4.0 <=5.4.9>=5.5.0 <=5.5.5

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 16:28:24 UTC

Technical Analysis

The Head Mare advanced persistent threat group exploited a chain of vulnerabilities (KLCERT-26-057 and KLCERT-26-058) in TrueConf video conferencing servers to gain unauthorized access via TCP port 4307. These vulnerabilities allowed execution of arbitrary code with NT AUTHORITY\SYSTEM privileges. The attackers replaced legitimate TrueConf client installers with versions infected by the PhantomCore backdoor and deployed a web shell to maintain persistent access. Additionally, the PhantomGraph backdoor leveraged Microsoft OneDrive as its command-and-control infrastructure. The affected TrueConf versions are 5.3.x through 5.3.9, 5.4.x through 5.4.9, and 5.5.x through 5.5.5. The campaign targeted multiple Russian organizations in sectors including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were officially patched in June 2026.

Potential Impact

Successful exploitation results in unauthorized remote code execution with SYSTEM-level privileges on TrueConf servers, enabling attackers to deploy persistent backdoors (PhantomCore and PhantomGraph). This compromises the confidentiality, integrity, and availability of affected systems and potentially the broader network. The use of legitimate client installer replacement and web shells increases stealth and persistence. The PhantomGraph backdoor's use of Microsoft OneDrive for command-and-control complicates detection and mitigation.

Defensive Guidance

The vulnerabilities in TrueConf servers were patched in June 2026. Organizations using affected versions should apply these official patches immediately to remediate the vulnerabilities. Since this is not a cloud service, remediation depends on patching the on-premises TrueConf servers. No vendor advisory content contradicts this; thus, patching is the primary mitigation. Additional detection and removal of the PhantomCore and PhantomGraph backdoors may be necessary if compromise is suspected.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"]
Adversary
Head Mare
Pulse Id
6a7b3ea2ac324259cbd21dc6
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip194.87.239.71
ip194.87.93.153
ip31.59.102.61
ip38.244.205.244
ip81.177.32.12

Hash

ValueDescriptionCopy
hash0e4541c3153ec5ed01497f19cf4f63d0
hash0e79996d9483d1e44fea32b0a48c2c19
hash129462164a7d52e9ea8560b60f0412c5
hash12d4e8f5295f2ef7e0f9bfc0f4830939
hash2bb75c20e778eb5c416965bd4d4259b1
hash43f435c3c437bc879a2d7d4634f43494
hash489f43be558b2679284ceabed7adc4f3
hash4d27b4eb1c5dbb3d8160f29b8119523e
hash748c9f8cb1065000616204935f96207f
hash7f267006cac10f341c356b62fe493527
hash8fcc3e4ccbf1725d9989fb464abf3561
hashaee9642b45b099cb7f3053b9b680b425
hashb348642146ea34771e5785c5857950f5
hashb3a6fee3307f1c26841fd5c603e2b013
hashc3a2abe8756910f42582b04a44ea3514
hashc5a460e4e68a088f6e51b2c6474642ec
hashc915cb6c2aeb863ee8479238e1644217
hashdd1fd2b459b97b7d59375cb8383cd19a
hashec0bf4a2186a88874e9f26f07cfeb532
hashee2861d5965e8730708cd1da8a93fa4c
hash7b9c37d82be5102e47a267e9f3c7c16b23bb1114
hashac9f013ad20aab607264d7cfe69ad153a4224d4b
hashb7cea387205e16c9f43d750035e77735415dad34
hashce1ae52bd60bf4a15a8d9aa597989b0d9df8ff3b
hashf9a692dadf9cc72352b979b1ecb80eb09ddf941a
hash0ed9306deabddaa587ad75d0775f7e63b27857a13adcc870dc9f8c92a9ddc6da
hash0fce4b732ce10c72093587e82ca9747a885430e366934ddc27e437443ff0cc0e
hash72029a4d4790784dd3029d13e73f57494dcb8f8187ca234b131e2b825bd84336
hashb9e4052b310f9451eca9784a4a33bf5282d1bd07e3359eba9648be625e2e40dd
hashceea2f175eaa02919e8b5161c2ecf585de3e8b6d586bca8046eee2e3f4efa386
hash4bbe23daa43583037420ff17b6c6d0844523037c
hash67bdd48ca58910cc5da499edc8a2b891dc9dc18a

Domain

ValueDescriptionCopy
domainpenzadogshelter.site
domainurbanpixel.store
domainvks.gossopka.forum

Threat ID: 6a7b42aabf8831d539f886e8

Added to database: 08/11/2026, 15:41:30 UTC

Last enriched: 08/11/2026, 16:28:24 UTC

Last updated: 08/12/2026, 03:02:24 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses