hacker-news · Crawled Aug 10, 2026
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
5 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
The threat actor Head Mare has exploited vulnerabilities in unpatched TrueConf servers to replace legitimate client installers with malicious versions delivering the PhantomCore backdoor and RAT. The attack chain involves exploiting two vulnerabilities, KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution with SYSTEM privileges, deploy a web shell, and substitute legitimate installers. The attackers also deploy a secondary backdoor, PhantomGraph, composed of two DLLs that exfiltrate data via Microsoft OneDrive and establish persistence through PowerShell commands.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 14 techniques
T1003.001 LSASS Memory · Credential Access T1059.001 PowerShell · Execution T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1087.001 Local Account · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1135 Network Share Discovery · Discovery T1485 Data Destruction · Impact T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1573 Encrypted Channel · Command And Control T1588 Obtain Capabilities · Resource Development