hacker-news · Crawled Aug 10, 2026

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

5 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

The threat actor Head Mare has exploited vulnerabilities in unpatched TrueConf servers to replace legitimate client installers with malicious versions delivering the PhantomCore backdoor and RAT. The attack chain involves exploiting two vulnerabilities, KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution with SYSTEM privileges, deploy a web shell, and substitute legitimate installers. The attackers also deploy a secondary backdoor, PhantomGraph, composed of two DLLs that exfiltrate data via Microsoft OneDrive and establish persistence through PowerShell commands.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 5 extracted

Type Value Detail
Domain sina[.]com Details →
Domain mirrors[.]ustc[.]edu[.]cn Details →
Filename wtsapi32.dll Details →
Filename locale.php Details →
Filename itcsrvup64.exe Details →

MITRE ATT&CK TTPs 14 techniques