At a glance
| Actor/group | Head Mare (tracked by Kaspersky; reclassified from hacktivist group to APT) |
| Activity type | Exploitation of unpatched TrueConf server flaws to distribute a trojanized client and backdoors |
| Targets/victims | Russian organizations across instrument manufacturing, electronics, transportation, energy, IT, and software development; any participant connecting to a compromised TrueConf server |
| Scale | No specific victim count disclosed; Kaspersky reports several active Head Mare campaigns ongoing |
| Jurisdiction/law enforcement | No law enforcement action reported; TrueConf has patched the exploited flaws |
| Source | Kaspersky (Securelist and Kaspersky ICS CERT) |
TL;DR: Kaspersky researchers detected a Head Mare TrueConf attack in July 2026 that chains two previously unknown vulnerabilities. The attackers gain full control of an unpatched TrueConf video conferencing server, then use it to distribute a trojanized client installer carrying the PhantomCore backdoor. Kaspersky reclassified Head Mare from a hacktivist group to an APT after this campaign, citing multi-stage exploitation and the absence of destructive wiping activity.
What Happened
Attackers connect to a TrueConf server over port 4307, which the vendor’s documentation lists as open by default. From there, they call a server function to upload and run a malicious script, using a flaw Kaspersky tracks internally as KLCERT-26-057. That script executes inside an isolated environment with no direct access to the operating system. A second flaw, KLCERT-26-058, lets the attackers break out of that isolation and run commands as NT AUTHORITY\SYSTEM, the highest privilege level on Windows. Once inside, they replace a legitimate file, locale.php, with a web shell used for ongoing remote access. The attackers use that access to study the target’s IT infrastructure, reach the TrueConf database, and swap the real TrueConf client installer for one carrying PhantomCore. To keep PhantomCore running after a reboot, the malware registers itself through a Windows registry key that loads it automatically at startup.
Who Is Behind It
Kaspersky attributes this Head Mare TrueConf attack to the Head Mare group, based mainly on code overlap between tools. Kaspersky wrote that “the program’s code partially matches that of PhantomCore,” which the company says ties the newer PhantomGraph backdoor to Head Mare’s existing toolset. That attribution rests on shared code, not a confirmed identity behind the group. The group’s activity extends well beyond this one campaign. Kaspersky tracks several active Head Mare operations against Russian organizations across instrument manufacturing, electronics, transportation, energy, IT, and software development. The group also distributes backdoors through phishing and compromised subcontractors, not just server flaws.
Impact and Scale
No source has confirmed how many organizations Head Mare compromised through this specific TrueConf campaign. Kaspersky describes the broader threat as several active campaigns, not a single incident. The company recommends every organization using TrueConf update to the patched versions, 5.3.9, 5.4.9, or 5.5.5, released June 18, 2026. Because a compromised server can infect any participant’s device, the impact reaches beyond an organization’s own TrueConf deployment. Employees who join a call hosted by a compromised partner could download an infected installer, even if their own employer never runs TrueConf at all. Beyond PhantomCore, the attackers also install a second backdoor, PhantomGraph, which the group operates through a Microsoft OneDrive account acting as its command-and-control channel.
What Comes Next
Kaspersky recommends verifying that any TrueConf client installer carries a valid digital signature before running it. The malicious installers used in this Head Mare TrueConf attack lacked that signature entirely. Organizations can also confirm installer authenticity directly on TrueConf’s website. Kaspersky’s endpoint detection tools already flag the PhantomCore and PhantomGraph backdoors under several detection names. Security teams building their own detection rules should watch for LSASS memory access, unsigned TrueConf installers, and unexpected services created from temporary directories.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.