Cyber Security News

Hackers Exploit TrueConf Servers to Push Malware Through Legitimate Video Conference Downloads

Kaspersky researchers investigating attacks on Russian organizations discovered that legitimate TrueConf video conferencing client installers were secretly bundled with PhantomCore malware, a tool associated with the Head Mare APT group.

The malicious installers were distributed directly from a TrueConf server belonging to the victim organization, making the attack especially deceptive since employees believed they were downloading trusted software.

The attackers chained two vulnerabilities, tracked internally as KLCERT-26-057 and KLCERT-26-058, to execute arbitrary code on TrueConf servers.

Hackers Exploit TrueConf Servers

The first flaw allowed an unauthenticated attacker to connect to port 4307/TCP and call an undocumented function to run a malicious script.

The second vulnerability let attackers break out of an isolated execution environment and run code with NT AUTHORITY\SYSTEM privileges, granting full control of the server.

With system-level access, attackers replaced a legitimate server file with a malicious web shell, which they used to map the victim’s IT infrastructure, gain privileged database access, and replace legitimate client installers with infected ones.

On Windows systems, they installed backdoor services named SysExcSvc and SysReadSvc that communicated via Microsoft OneDrive as a command-and-control channel.

On Linux systems, attackers deployed a separate backdoor that hides its files, intercepts TrueConf network traffic, and uses GitHub for command-and-control.

Anyone joining a video call hosted on a compromised server received a prompt urging them to download a new client application.

That installer quietly deployed the legitimate TrueConf client alongside a hidden PhantomCore payload disguised as a DLL, granting attackers remote command execution and full control over the infected workstation.

A registry key was created to ensure the malware automatically launched at every system startup. Kaspersky warns that even organizations not running TrueConf servers could be affected if employees join meetings hosted on compromised third-party or contractor servers.

TrueConf fixed both vulnerabilities in server versions 5.3.9, 5.4.9, and 5.5.5, released on June 18, 2026. Kaspersky noted that internal analysis found every TrueConf server version released since 2022 was vulnerable before the patch.

The vendor is actively notifying administrators to update immediately, while Kaspersky continues coordinating disclosure and remediation support.

Security teams should update TrueConf servers to the patched versions immediately and scan environments for indicators of compromise that Kaspersky published, including specific file hashes, suspicious file paths, malicious domains, and unusual service names such as SysExcSvc and SysReadSvc.

TypeKey IoCs
File Hashes (MD5)748c9f8cb1065000616204935f96207f — Malicious TrueConf installer
c5a460e4e68a088f6e51b2c6474642ec — PhantomCore
489f43be558b2679284ceabed7adc4f3 — PhantomGraph
IP Addresses81.177.32[.]12194.87.239[.]71194.87.93[.]15338.244.205[.]244
Domainspenzadogshelter[.]sitetrendy-market[.]sitebright-deals[.]sitenova-stream[.]site
Windows ServicesSysExcSvcSysReadSvc
Malicious PathsC:\Windows\System32\inetsrv\SysExcSvc.dllC:\Windows\System32\inetsrv\SysReadSvc.dll%LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll
Detection NamesBackdoor.Win64.PhantomCoreTrojan.Win64.PhantomGraphBackdoor.PHP.WebShell

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Organizations should also run full antivirus scans with updated definitions and reset passwords for any accounts suspected of exposure. If compromise indicators are found, Kaspersky recommends contacting its ICS CERT team for further investigation support.

This incident highlights how trust in communication software’s supply chain can be weaponized, turning a routine app download into a full system compromise. Detailed malware analysis and additional attack details are expected in a forthcoming Kaspersky Threat Intelligence Portal report.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago