Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
AI Summary
In July 2026, the APT group Head Mare exploited two previously unknown vulnerabilities in unpatched TrueConf servers (versions 5.3.x through 5.5.5) to gain SYSTEM-level access and deploy web shells. The attackers replaced legitimate TrueConf client installers with malicious versions containing the PhantomCore backdoor, which was used to compromise video conference participants. A second backdoor, PhantomGraph, composed of SysExcSvc.dll and SysReadSvc.dll, was also deployed to establish persistence and execute commands via Base64-encoded PowerShell scripts. The group targeted Russian organizations across multiple sectors, using compromised servers and phishing to distribute malware. Kaspersky has detected the activity and provided indicators and detection rules.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 31 extracted
| Type | Value | Detail |
|---|---|---|
| MD5 | 4d27b4eb1c5dbb3d8160f29b8119523e | Details → |
| MD5 | 748c9f8cb1065000616204935f96207f | Details → |
| MD5 | c5a460e4e68a088f6e51b2c6474642ec | Details → |
| MD5 | 129462164a7d52e9ea8560b60f0412c5 | Details → |
| MD5 | ec0bf4a2186a88874e9f26f07cfeb532 | Details → |
| MD5 | b348642146ea34771e5785c5857950f5 | Details → |
| MD5 | c915cb6c2aeb863ee8479238e1644217 | Details → |
| MD5 | 0e79996d9483d1e44fea32b0a48c2c19 | Details → |
| MD5 | 2bb75c20e778eb5c416965bd4d4259b1 | Details → |
| MD5 | b3a6fee3307f1c26841fd5c60f04b013 | Details → |
| MD5 | 8fcc3e4ccbf1725d9989fb464abf3561 | Details → |
| MD5 | 489f43be558b2679284ceabed7adc4f3 | Details → |
| MD5 | dd1fd2b459b97b7d59375cb8383cd19a | Details → |
| MD5 | 0e4541c3153ec5ed01497f19cf4f63d0 | Details → |
| MD5 | 12d4e8f5295f2ef7e0f9bfc0f4830939 | Details → |
| MD5 | 7f267006cac10f341c356b62fe493527 | Details → |
| MD5 | ee2861d5965e8730708cd1da8a93fa4c | Details → |
| MD5 | c3a2abe8756910f42582b04a44ea3514 | Details → |
| MD5 | 43f435c3c437bc879a2d7d4634f43494 | Details → |
| MD5 | aee9642b45b099cb7f3053b9b680b425 | Details → |
| IP | 81[.]177[.]32[.]12 | Details → |
| IP | 194[.]87[.]239[.]71 | Details → |
| IP | 194[.]87[.]93[.]153 | Details → |
| IP | 38[.]244[.]205[.]244 | Details → |
| IP | 31[.]59[.]102[.]61 | Details → |
| Domain | penzadogshelter[.]site | Details → |
| Domain | trendy-market[.]site | Details → |
| Domain | bright-deals[.]site | Details → |
| Domain | nova-stream[.]site | Details → |
| Domain | rinomobile[.]ink | Details → |
| Domain | urbanpixel[.]store | Details → |