securelist · Crawled Aug 12, 2026

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

31 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

In July 2026, the APT group Head Mare exploited two previously unknown vulnerabilities in unpatched TrueConf servers (versions 5.3.x through 5.5.5) to gain SYSTEM-level access and deploy web shells. The attackers replaced legitimate TrueConf client installers with malicious versions containing the PhantomCore backdoor, which was used to compromise video conference participants. A second backdoor, PhantomGraph, composed of SysExcSvc.dll and SysReadSvc.dll, was also deployed to establish persistence and execute commands via Base64-encoded PowerShell scripts. The group targeted Russian organizations across multiple sectors, using compromised servers and phishing to distribute malware. Kaspersky has detected the activity and provided indicators and detection rules.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 31 extracted

Type Value Detail
MD5 4d27b4eb1c5dbb3d8160f29b8119523e Details →
MD5 748c9f8cb1065000616204935f96207f Details →
MD5 c5a460e4e68a088f6e51b2c6474642ec Details →
MD5 129462164a7d52e9ea8560b60f0412c5 Details →
MD5 ec0bf4a2186a88874e9f26f07cfeb532 Details →
MD5 b348642146ea34771e5785c5857950f5 Details →
MD5 c915cb6c2aeb863ee8479238e1644217 Details →
MD5 0e79996d9483d1e44fea32b0a48c2c19 Details →
MD5 2bb75c20e778eb5c416965bd4d4259b1 Details →
MD5 b3a6fee3307f1c26841fd5c60f04b013 Details →
MD5 8fcc3e4ccbf1725d9989fb464abf3561 Details →
MD5 489f43be558b2679284ceabed7adc4f3 Details →
MD5 dd1fd2b459b97b7d59375cb8383cd19a Details →
MD5 0e4541c3153ec5ed01497f19cf4f63d0 Details →
MD5 12d4e8f5295f2ef7e0f9bfc0f4830939 Details →
MD5 7f267006cac10f341c356b62fe493527 Details →
MD5 ee2861d5965e8730708cd1da8a93fa4c Details →
MD5 c3a2abe8756910f42582b04a44ea3514 Details →
MD5 43f435c3c437bc879a2d7d4634f43494 Details →
MD5 aee9642b45b099cb7f3053b9b680b425 Details →
IP 81[.]177[.]32[.]12 Details →
IP 194[.]87[.]239[.]71 Details →
IP 194[.]87[.]93[.]153 Details →
IP 38[.]244[.]205[.]244 Details →
IP 31[.]59[.]102[.]61 Details →
Domain penzadogshelter[.]site Details →
Domain trendy-market[.]site Details →
Domain bright-deals[.]site Details →
Domain nova-stream[.]site Details →
Domain rinomobile[.]ink Details →
Domain urbanpixel[.]store Details →

MITRE ATT&CK TTPs 14 techniques