If your organization runs TrueConf server software, check the version before the weekend. Kaspersky has flagged an active attack wave that exploits two chained flaws in unpatched builds to swap genuine client installers for malware.
The campaign, detected in July 2026, targeted Russian companies in instrumentation, electronics, transport, energy, IT, and software development. Kaspersky attributes it to Head Mare, the group that abused TrueConf zero-days as far back as last September.
The two bugs, KLCERT-26-057 and KLCERT-26-058, combine into arbitrary code execution with elevated privileges. Attackers open a connection to the server’s default TCP port 4307, use the first flaw to run a script in a sandbox, then leverage the second to escape that sandbox and run commands on the host with SYSTEM rights.
A web shell placed over the locale.php file then gives persistent remote access. Kaspersky watched it being used to map the network, reach the TrueConf database, and replace the original client package with an infected copy that drops the PhantomCore RAT.
The same shell delivered PhantomGraph, a second backdoor split across two DLLs installed as Windows services. SysExcSvc.dll receives commands and forwards results to OneDrive, which doubles as command-and-control; SysReadSvc.dll parses and executes them. Kaspersky thinks the two-module split is designed to evade endpoint detection.
Operators also set up SSH reverse tunnels, dumped lsass.exe memory, and pulled basic system information via commands like hostname and whoami.
Fixed versions shipped June 18, 2026: 5.3.9, 5.4.9, and 5.5.5. Until patched, vulnerable servers remain exposed through the default-open management port.
