TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Overview
A group known as Head Mare has been exploiting vulnerabilities in unpatched TrueConf servers to carry out attacks against various Russian companies. These companies operate in sectors like instrumentation, electronics, transport, energy, IT, and software development. Kaspersky, a cybersecurity firm, reported detecting these attacks in July 2026. The attackers are reportedly replacing legitimate client installers with malicious software called PhantomCore, which could compromise the security of the affected organizations. This situation raises concerns for companies still using outdated versions of TrueConf, as failure to update could lead to severe security breaches.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: TrueConf servers, specifically unpatched versions used by Russian companies in various sectors.
- Action Required: Companies should update their TrueConf servers to the latest versions as soon as possible to mitigate the risk of exploitation.
- Timeline: Ongoing since July 2026
Original Article Summary
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain
Impact
TrueConf servers, specifically unpatched versions used by Russian companies in various sectors.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since July 2026
Remediation
Companies should update their TrueConf servers to the latest versions as soon as possible to mitigate the risk of exploitation.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Update, Malware, and 1 more.