Security researchers at Kaspersky have uncovered a sophisticated campaign targeting Russian organizations in which threat actors leveraged compromised TrueConf servers to distribute PhantomCore malware, a tool linked to the Head Mare advanced persistent threat (APT) group.
The investigation revealed that legitimate TrueConf video conferencing client installers had been tampered with and bundled with malicious code. Because the infected installers were served directly from trusted TrueConf servers belonging to victim organizations, employees had little reason to suspect the downloads were malicious.
The attackers reportedly exploited two server vulnerabilities, designated KLCERT-26-057 and KLCERT-26-058, to gain complete control of affected TrueConf environments.
The first vulnerability enabled unauthenticated access to port 4307/TCP, allowing attackers to invoke an undocumented function and execute malicious scripts remotely. The second flaw permitted attackers to escape the application's isolated execution environment and elevate privileges to NT AUTHORITY\SYSTEM, effectively granting them full administrative control of the server.
After compromising the servers, the threat actors replaced a legitimate file with a malicious web shell. This foothold allowed them to conduct reconnaissance, map internal networks, obtain privileged database access, and swap legitimate client installers with trojanized versions containing malware.
On Windows systems, attackers deployed backdoor services named SysExcSvc and SysReadSvc, using Microsoft OneDrive as a command-and-control (C2) channel. Linux systems were targeted with a separate backdoor capable of concealing files, intercepting TrueConf traffic, and communicating with operators through GitHub-based C2 infrastructure.
Users connecting to meetings hosted on compromised servers were prompted to download what appeared to be an updated TrueConf client. While the installer successfully deployed the legitimate conferencing application, it also secretly installed a PhantomCore payload disguised as a DLL file. This malware granted attackers remote execution capabilities and complete control over infected endpoints.
To maintain persistence, the malware created registry entries that ensured it launched automatically whenever the system restarted. Kaspersky warned that exposure is not limited to organizations operating their own TrueConf servers. Any user joining meetings hosted on compromised third-party or contractor servers could also become a victim.
TrueConf addressed both vulnerabilities in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18, 2026. According to Kaspersky, every TrueConf server version released since 2022 was vulnerable until these patches became available. The vendor is actively urging administrators to upgrade immediately while Kaspersky continues to support remediation and coordinated disclosure efforts.
Security teams are advised to update vulnerable systems without delay and inspect their environments for indicators of compromise (IOCs) published by Kaspersky, including specific file hashes, suspicious file locations, malicious domains, and unusual services such as SysExcSvc and SysReadSvc.
As a precaution, organizations should perform full antivirus scans with current signatures, review potentially exposed accounts, and reset passwords where compromise is suspected. If evidence of intrusion is discovered, Kaspersky recommends engaging its ICS CERT team for additional incident response and forensic assistance.

The incident serves as a reminder of how trusted software distribution channels can be weaponized by threat actors. By compromising the software supply chain, attackers transformed routine application downloads into a highly effective malware delivery mechanism. Kaspersky is expected to release further technical details and malware analysis in an upcoming Threat Intelligence Portal report.
Note: Any IP addresses and domains shared as indicators have been intentionally defanged (for example, replacing "." with "[.]") to prevent accidental access. These indicators should only be reactivated within controlled threat intelligence platforms, such as MISP, VirusTotal, or enterprise SIEM solutions.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
