{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/trueconf-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["Head Mare"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TrueConf Server"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["TrueConf"],"content_html":"\u003cp\u003eSince July 2026, the Head Mare APT group has been observed exploiting a chain of vulnerabilities in TrueConf Server (versions 5.3.x, 5.4.x, and 5.5.x) to compromise enterprise conferencing infrastructure. The attackers leverage unauthorized access via TCP port 4307 to trigger remote code execution within an isolated environment, subsequently escalating privileges to NT AUTHORITY\\SYSTEM. Once local system access is achieved, the threat actors deploy a PHP web shell ('locale.php') to maintain persistence, conduct infrastructure reconnaissance, and perform supply chain attacks by replacing legitimate TrueConf client installers with versions containing the PhantomCore backdoor. The group further deploys a modular backdoor, PhantomGraph, which uses Microsoft OneDrive for command-and-control communications and establishes persistence through malicious Windows services and registry modifications. This campaign targets critical infrastructure sectors, including energy, manufacturing, and IT, across Russia.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttackers establish unauthorized connection to the target TrueConf server via TCP port 4307.\u003c/li\u003e\n\u003cli\u003eAttackers transmit and execute a malicious script on the server by exploiting vulnerability KLCERT-26-057.\u003c/li\u003e\n\u003cli\u003eAttackers exploit vulnerability KLCERT-26-058 to escape the isolated execution environment and gain arbitrary code execution.\u003c/li\u003e\n\u003cli\u003eExecution occurs in the context of the NT AUTHORITY\\SYSTEM account on the Windows host.\u003c/li\u003e\n\u003cli\u003eAttackers overwrite the '...\\public\\js\\locale.php' file with a web shell to maintain persistent remote access.\u003c/li\u003e\n\u003cli\u003eThe web shell is used to perform internal reconnaissance and gain administrative access to the TrueConf database.\u003c/li\u003e\n\u003cli\u003eAttackers inject the PhantomCore backdoor into legitimate TrueConf client installation files.\u003c/li\u003e\n\u003cli\u003eAttackers deploy PhantomGraph modules ('SysExcSvc.dll' and 'SysReadSvc.dll') via PowerShell as Windows services, utilizing OneDrive for C2.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise, data exfiltration from conferencing databases, and supply chain attacks against participants who download backdoored client software. Observed targeting includes critical industries such as energy, transportation, and software development, impacting the integrity of internal communications and potentially providing a pivot point into the broader corporate network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all TrueConf Server instances to versions 5.3.9, 5.4.9, or 5.5.5 immediately to remediate the vulnerabilities.\u003c/li\u003e\n\u003cli\u003eVerify the digital signature of all TrueConf client installer files against the official vendor authenticity guidelines to ensure they have not been tampered with.\u003c/li\u003e\n\u003cli\u003eDeploy detection for the creation of non-standard PHP files in the TrueConf installation directory, specifically monitoring for modifications to 'locale.php'.\u003c/li\u003e\n\u003cli\u003eEnable EDR telemetry on all servers hosting TrueConf applications to monitor for unauthorized PowerShell execution and the registration of new Windows services.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-11T17:45:55Z","date_published":"2026-08-11T17:45:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-head-mare-trueconf/","summary":"The Head Mare APT group is exploiting a chain of vulnerabilities in TrueConf Server to achieve remote code execution as SYSTEM and distribute backdoored installer packages to victims.","title":"Head Mare APT Exploiting TrueConf Server Vulnerabilities to Deploy PhantomCore and PhantomGraph","url":"https://feed.craftedsignal.io/briefs/2026-08-head-mare-trueconf/"}],"language":"en","title":"CraftedSignal Threat Feed - TrueConf Server","version":"https://jsonfeed.org/version/1.1"}