Kaspersky researchers investigating attacks on Russian organizations discovered that legitimate TrueConf video conferencing client installers were secretly bundled with PhantomCore malware, a tool associated with the Head Mare APT group.
The malicious installers were distributed directly from a TrueConf server belonging to the victim organization, making the attack especially deceptive since employees believed they were downloading trusted software.
The attackers chained two vulnerabilities, tracked internally as KLCERT-26-057 and KLCERT-26-058, to execute arbitrary code on TrueConf servers.
The first flaw allowed an unauthenticated attacker to connect to port 4307/TCP and call an undocumented function to run a malicious script.
The second vulnerability let attackers break out of an isolated execution environment and run code with NT AUTHORITY\SYSTEM privileges, granting full control of the server.
With system-level access, attackers replaced a legitimate server file with a malicious web shell, which they used to map the victim’s IT infrastructure, gain privileged database access, and replace legitimate client installers with infected ones.
On Windows systems, they installed backdoor services named SysExcSvc and SysReadSvc that communicated via Microsoft OneDrive as a command-and-control channel.
On Linux systems, attackers deployed a separate backdoor that hides its files, intercepts TrueConf network traffic, and uses GitHub for command-and-control.
Anyone joining a video call hosted on a compromised server received a prompt urging them to download a new client application.
That installer quietly deployed the legitimate TrueConf client alongside a hidden PhantomCore payload disguised as a DLL, granting attackers remote command execution and full control over the infected workstation.
A registry key was created to ensure the malware automatically launched at every system startup. Kaspersky warns that even organizations not running TrueConf servers could be affected if employees join meetings hosted on compromised third-party or contractor servers.
TrueConf fixed both vulnerabilities in server versions 5.3.9, 5.4.9, and 5.5.5, released on June 18, 2026. Kaspersky noted that internal analysis found every TrueConf server version released since 2022 was vulnerable before the patch.
The vendor is actively notifying administrators to update immediately, while Kaspersky continues coordinating disclosure and remediation support.
Security teams should update TrueConf servers to the patched versions immediately and scan environments for indicators of compromise that Kaspersky published, including specific file hashes, suspicious file paths, malicious domains, and unusual service names such as SysExcSvc and SysReadSvc.
| Type | Key IoCs |
|---|---|
| File Hashes (MD5) | 748c9f8cb1065000616204935f96207f — Malicious TrueConf installerc5a460e4e68a088f6e51b2c6474642ec — PhantomCore489f43be558b2679284ceabed7adc4f3 — PhantomGraph |
| IP Addresses | 81.177.32[.]12194.87.239[.]71194.87.93[.]15338.244.205[.]244 |
| Domains | penzadogshelter[.]sitetrendy-market[.]sitebright-deals[.]sitenova-stream[.]site |
| Windows Services | SysExcSvcSysReadSvc |
| Malicious Paths | C:\Windows\System32\inetsrv\SysExcSvc.dllC:\Windows\System32\inetsrv\SysReadSvc.dll%LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll |
| Detection Names | Backdoor.Win64.PhantomCoreTrojan.Win64.PhantomGraphBackdoor.PHP.WebShell |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Organizations should also run full antivirus scans with updated definitions and reset passwords for any accounts suspected of exposure. If compromise indicators are found, Kaspersky recommends contacting its ICS CERT team for further investigation support.
This incident highlights how trust in communication software’s supply chain can be weaponized, turning a routine app download into a full system compromise. Detailed malware analysis and additional attack details are expected in a forthcoming Kaspersky Threat Intelligence Portal report.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…