Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Overview
Researchers at Kaspersky have identified a cybersecurity threat involving the Head Mare APT group, which is exploiting vulnerabilities in unpatched TrueConf servers. This group is using malicious software installers to deliver two backdoors, PhantomCore and PhantomGraph, to users participating in video conferences. The attack specifically targets systems that have not updated their TrueConf software, making them susceptible to these exploits. This situation raises significant concerns for organizations that rely on video conferencing tools for communication, as attackers could gain unauthorized access to sensitive information. Users and companies should prioritize patching their TrueConf installations to mitigate this risk.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: TrueConf servers, users of TrueConf video conferencing software
- Action Required: Update to the latest version of TrueConf software to patch vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
Impact
TrueConf servers, users of TrueConf video conferencing software
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Update to the latest version of TrueConf software to patch vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, APT, Malware, and 1 more.