Head Mare breached TrueConf servers to push backdoored video-conferencing client updates

Hackers used flaws in TrueConf video-conferencing servers to break in and replace legitimate client installers with malware-laced versions, putting organizations and even outside meeting participants at risk. Kaspersky says Head Mare exploited two TrueConf Server bugs it tracks as KLCERT-26-057 and KLCERT-26-058 on TCP port 4307 to get unauthenticated code execution, escape the product's sandbox, gain NT AUTHORITY\SYSTEM, install a web shell, and deploy PhantomCore and PhantomGraph. Affected versions are 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5; fixes were released June 18.
Why it matters: Organizations running on-premises TrueConf servers should patch immediately and treat unpatched servers as potentially compromised, because attackers can turn normal software updates into malware delivery. This also affects users who connect to a partner's compromised TrueConf server, so admins should verify installer signatures and hunt for web shells, LSASS credential dumping, and PhantomCore or PhantomGraph artifacts.

Sources

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
2026.08.21 95% relevant
This is the same underlying exploitation campaign and vulnerability pair, adding that CISA has now placed CVE-2026-72529 and CVE-2026-72530 in the KEV catalog and ordered U.S. federal agencies to patch by September 10, confirming active exploitation beyond just the earlier vendor and researcher reporting.
CISA orders feds to patch actively exploited TrueConf Server flaws
Sergiu Gatlan 2026.08.21 95% relevant
This article directly updates that same underlying event by adding that CISA has now placed the two exploited TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, in the KEV catalog and ordered federal agencies to patch by September 3, confirming active exploitation beyond the earlier Kaspersky reporting.
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
Ionut Arghire 2026.08.21 96% relevant
This article updates the same underlying exploitation campaign by adding that CISA has now formally added CVE-2026-72529 and CVE-2026-72530 in TrueConf Server to the KEV catalog, set federal remediation deadlines, and reiterated patch versions 5.3.9, 5.4.9, and 5.5.5.
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
info@thehackernews.com (The Hacker News) 2026.08.10 99% relevant
This is the same underlying event: Head Mare exploited TrueConf Server flaws to replace legitimate client installers with PhantomCore malware, updating or corroborating the existing report about backdoored TrueConf client distributions.
Hackers breach TrueConf to trojanize client installers with backdoors
Bill Toulas 2026.08.08 100% relevant
This article establishes a distinct ongoing intrusion campaign against TrueConf servers in which exploited server flaws are used to trojanize downstream client installers with PhantomCore and PhantomGraph.
← Back to all stories