Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

TrueConf Server Flaws Exploited to Reveal Sophisticated Phishing Attacks Targeting Russian Entities




A recent attack by threat actor Head Mare has leveraged zero-day flaws in TrueConf servers to deliver a range of malicious payloads targeting Russian entities. The attackers have been observed using these vulnerabilities to gain elevated privileges, deploy PhantomCore backdoors and remote access trojans (RATs), and evade detection. This highlights the importance of prioritizing software patching and taking proactive steps against such sophisticated phishing attacks.



  • A recent phishing attack campaign by threat actor Head Mare targets Russian entities using vulnerabilities in TrueConf servers.
  • The attacks exploit previously unreported zero-day flaws, allowing attackers to gain elevated privileges and deploy highly sophisticated malware.
  • The vulnerability chain involves initial connection to the TrueConf server, exploitation of two specific vulnerabilities, and deployment of web shells and remote access trojans (RATs).
  • The attackers also deployed a second piece of malware codenamed PhantomGraph, which includes DLL modules for receiving commands and exfiltrating results.
  • Organizations using TrueConf are advised to download the latest versions for optimal protection against these attacks.



  • A recent discovery by cybersecurity vendor Kaspersky has shed light on a sophisticated phishing attack campaign targeting Russian entities, leveraging vulnerabilities in TrueConf servers to deliver a range of malicious payloads. The attacks, attributed to the threat actor known as Head Mare, have been linked to previously unreported zero-day flaws in the software, allowing the attackers to gain elevated privileges and deploy highly sophisticated malware.

    According to Kaspersky, the vulnerability chain exploited by Head Mare begins with an initial connection to the TrueConf server on TCP port 4307, which is open by default. The attackers then exploit two specific vulnerabilities, tracked as KLCERT-26-057 and KLCERT-26-058, to run malicious scripts on the server, limiting their access to operating system functions. This isolation allows the attackers to maintain control while minimizing the risk of detection.

    The next stage of the attack involves exploiting these isolated environments to execute arbitrary commands on the underlying host with NT AUTHORITY\SYSTEM privileges. To further obscure their activities, the attackers replace the file "...\public\js\locale.php" with a web shell, facilitating persistent remote access to the compromised server. This web shell has been leveraged to collect data on the IT infrastructure, gain privileged access to the TrueConf database, and ultimately substitute the original TrueConf Client distribution with an infected version containing PhantomCore.

    In addition to delivering PhantomCore backdoors and remote access trojans (RATs), the attackers have also deployed a second piece of malware codenamed PhantomGraph. This malware includes two DLL modules - "SysExcSvc.dll" for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage, and "SysReadSvc.dll" for parsing the commands received by the first module, executing it, and storing the results.

    Furthermore, the attackers have been observed launching an SSH reverse tunnel, taking a memory dump of the "lsass.exe" process, and collecting general system information using commands like hostname and whoami. To evade detection, they have taken steps to interfere with the normal functioning of security solutions operating in user mode for filtering network connections.

    This latest discovery is part of a larger trend of threat actors targeting zero-day flaws in TrueConf to single out Russian entities. Positive Technologies had earlier disclosed that three vulnerabilities in the software were abused by the group since September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution. Check Point also reported that another high-severity security flaw in the TrueConf client was exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia.

    The findings highlight how widely-used programs in Russia are becoming lucrative vectors for advanced threat actors. Fake updates for ViPNet have been leveraged in prior attacks, and the discovery of new vulnerabilities in TrueConf serves as a reminder that no software is immune to exploitation. Organizations using TrueConf are advised to download the latest versions for optimal protection.

    The development comes weeks after Kaspersky said it discovered a new advanced persistent threat (APT)-style attack that has been ongoing since at least May 2026, using previously unreported tooling primarily by taking advantage of the update mechanism for the ViPNet product suite to target Russian government, energy, transport, education, and logistics sectors.

    The HelloNet attack involves the execution of a malicious DLL ("wtsapi32.dll") that masquerades as a legitimate file associated with the ViPNet suite update system. This loader DLL is sideloaded by the ViPNet update binary "itcsrvup64.exe," resulting in the execution of the malicious payload from within "svchost.exe."

    The attackers have been observed using this malware to deliver a range of payloads, including a hidden proxy and a loader for additional modules retrieved from a C2 server. This malware also serves as a conduit for another backdoor codenamed HelloExecutor, which executes commands on the infected system and launches an SSH tunnel to attacker infrastructure.

    The threat actors have also discovered a Rust implant named HelloBackdoor that can enable file uploads and downloads to and from the C2 server. Commands that do not match a predefined format are interpreted as instructions to be executed via "cmd.exe." This development underscores the complexity of modern malware attacks and highlights the need for ongoing vigilance in cybersecurity.

    The discovery of these vulnerabilities serves as a reminder of the importance of patching software, particularly for widely-used programs like TrueConf. Organizations must prioritize regular updates and take proactive steps to protect themselves against such sophisticated phishing attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/TrueConf-Server-Flaws-Exploited-to-Reveal-Sophisticated-Phishing-Attacks-Targeting-Russian-Entities-ehn.shtml

  • https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html


  • Published: Mon Aug 10 08:14:25 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us