Compromised TrueConf servers delivered backdoored installers

Published August 8, 2026

Head Mare took over unpatched TrueConf servers and replaced their trusted client installers. The altered updates installed PhantomCore, while attackers separately collected sensitive server information.

Report priority
High
Involves
TrueConf Server

What is known

  • The attacker connects to TCP port 4307, which TrueConf Server opens by default.
  • This connection does not require a login.
  • Two server flaws let the attacker run commands with the highest system privileges.
  • The attacker keeps remote access and replaces the legitimate client installer with a PhantomCore-infected copy.
  • Connected users then receive the unsigned installer as a TrueConf update.

What to do

Check your organization's TrueConf Server version. Versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and earlier releases are affected. An unsigned client installer offered by a TrueConf server is suspicious, but does not alone confirm infection.

Update the matching server branch to 5.3.9, 5.4.9, or 5.5.5. If users received an unsigned installer, ask the security team to examine the server and distributed installers.

Reported details

Kaspersky observed Head Mare compromising TrueConf servers and replacing their hosted client installers. The altered installers delivered PhantomCore to connected users. Attackers separately used server access to collect sensitive information and deployed PhantomGraph to extract credentials.

Head Mare exploited TrueConf Server flaws KLCERT-26-057 and KLCERT-26-058 through TCP port 4307 without authentication. The chain enabled commands with NT AUTHORITY\SYSTEM privileges and persistent remote access. Attackers collected server information and replaced the hosted client installer with a PhantomCore-infected version. They separately deployed PhantomGraph, which received commands through OneDrive and extracted credentials from server memory.