Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

Threat Overview

The Kaspersky Threat Report released on 2026-08-21 details a sophisticated attack by the Head Mare APT group that targets unpatched installations of the TrueConf video‑conferencing platform. By exploiting two internal vulnerabilities (KLCERT-26-057 and KLCERT-26-058) the attackers inject a malicious web shell, replace legitimate client installers with malware‑laden copies, and deploy the PhantomCore backdoor on both the server and client machines. The malicious installer is delivered through the TrueConf server’s default download page, making it difficult for users to distinguish it from a legitimate update.

Technical Details

For TrueConf servers running versions 5.3.X (before 5.3.9), 5.4.X (before 5.4.9), and 5.5.X (before 5.5.5) the attackers connect via the open port 4307/TCP and invoke an undocumented script execution endpoint. The initial script runs in a sandbox where standard libraries are unavailable, but a second vulnerability allows escalation to NT AUTHORITY\SYSTEM privileges. The compromised server then replaces the legitimate locale.php file with a malicious web shell that deletes related event logs, installs a backdoor service (SysExcSvc and SysReadSvc), and provides a covert command & control channel through a OneDrive account. On Unix‑based servers the attackers deploy a hidden backdoor that intercepts TrueConf network functions and uses GitHub as a C2 channel.

Once the client installer is executed on an end‑user machine, the TrueConf client is installed normally, but the PhantomCore malware is unpacked to %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll. The malware registers a startup key at HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32, enabling persistent execution and remote command execution via PowerShell.

Impact

Attackers can exfiltrate sensitive data, obtain privileged access to the TrueConf database, and manipulate conference content. Even organisations that do not host a TrueConf server are at risk because employees may connect to compromised servers run by contractors, downloading the infected installer and compromising their desktop. The use of well‑known cloud services (OneDrive, GitHub) as C2 infrastructure makes detection more challenging, as traffic appears legitimate.

Indicators of Compromise (IOCs)

  • File hashes (MD5): 4d27b4eb1c5dbb3d8160f29b8119523e (web shell), 748c9f8cb1065000616204935f96207f (installer), c5a460e4e68a088f6e51b2c6474642ec (PhantomCore backdoor), etc.
  • File paths: C:\Windows\System32\inetsrv\SysExcSvc.dll, %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll, /etc/systemd/system/omicluster.service, etc.
  • IP addresses (sanitized): 81[.]177[.]32[.]12, 194[.]87[.]239[.]71, 38[.]244[.]205[.]244, etc.
  • Domain names (sanitized): hxxps://penzadogshelter[.]site, hxxps://trendy-market[.]site, hxxps://urbanpixel[.]store, etc.

Recommendations

TrueConf server owners:

  • Upgrade immediately to the latest patch (5.3.9, 5.4.9, or 5.5.5) released on 2026-06-18.
  • Perform an IOC scan using up‑to‑date antivirus engines.
  • Change all administrative passwords and review account privileges.

All organisations:

  • Verify that no malicious installers are present in the corporate download repository.
  • Disable the default 4307/TCP port on servers that are not in use.
  • Monitor for anomalous registry keys, especially the CLSID entry used by PhantomCore.

For additional details and technical deep dives, consult the full Kaspersky Threat Intelligence Portal report. Organizations can also reach out to the incident response team at ics-cert@kaspersky.com.

Leave a Reply

Looking for the Best Cyber Security?

Seamlessly integrate local and cloud resources with our comprehensive cybersecurity services. Protect user traffic at endpoints using advanced security solutions like threat hunting and endpoint protection. Build a scalable network infrastructure with continuous monitoring, incident response, and compliance assessments.

Contact Us

Copyright © 2025 ESSGroup

Discover more from ESSGroup

Subscribe now to keep reading and get access to the full archive.

Continue reading