bleeping-computer · Crawled Aug 8, 2026
Hackers breach TrueConf to trojanize client installers with backdoors
4 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.
AI-extracted · verify before operational use