bleeping-computer · Crawled Aug 8, 2026

Hackers breach TrueConf to trojanize client installers with backdoors

4 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 4 extracted

Type Value Detail
IP TCP port 4307 Details →
Filename \public\js\locale.php Details →
Filename SysExcSvc.dll Details →
Filename SysReadSvc.dll Details →

MITRE ATT&CK TTPs 6 techniques