Hackers Exploit TrueConf Servers to Distribute Malware Through Fake Software Updates

Last updated: August 10, 2026 Reading time: 4 minutes
Disclosure
Share
Hackers Exploit TrueConf Servers to Distribute Malware Through Fake Software Updates
  • A hacker group named Head Mare broke into TrueConf video meeting servers and swapped safe installers for harmful ones.
  • The attackers used two software flaws to gain full control and plant two hidden tools called PhantomCore and PhantomGraph.
  • TrueConf has fixed the flaws in the new updates, but users who have not updated yet remain at risk.

A hacker group called Head Mare found weak spots in TrueConf video meeting servers. TrueConf is a video call tool that many Russian companies and government offices use instead of Zoom or Microsoft Teams.

Head Mare used these weak spots to swap the normal app installer with a fake one. That fake installer carried hidden backdoor tools onto victims’ computers.

The Attacks System of Operation 

Kaspersky, a cybersecurity firm, found this attack in July. According to Kaspersky, Head Mare connected to TrueConf servers through port 4307. This port stays open by default and needs no login. The hackers then used one flaw to run a harmful script inside TrueConf’s protected space. They used a second flaw to break out of that space and reach the main computer system.

After breaking out, the attackers gained the highest level of access on the machine, called NT AUTHORITY\SYSTEM. With this power, they replaced a file named locale.php with a web shell. A web shell lets hackers control a server from far away, any time they want.

What the Hackers Stole and Installed

Kaspersky reports that Head Mare used the web shell to grab private data from the server. They also reached the TrueConf database and swapped the real client installer with a fake one carrying the PhantomCore backdoor. When staff connected to their company’s TrueConf server, they downloaded this fake update without knowing it. The fake file carried no digital signature, a sign that it was not safe.

Kaspersky also warns that even companies that don’t run their own TrueConf server can get hit. Their staff might join a video call hosted on someone else’s infected server. They could download the bad file that way, without realizing it.

The hackers also planted a second tool called PhantomGraph. This tool uses two files to take commands through a Microsoft OneDrive account. It then carries out those commands and sends back the results.

Researchers saw the attackers use PhantomGraph to copy memory from a Windows security process called LSASS. This lets them steal login details. They also ran simple commands to learn about each computer and opened a hidden remote connection using SSH.

Who is at Risk and What to do

Kaspersky says Head Mare is now attacking many Russian companies. Targets include firms in instrument-making, electronics, transport, energy, IT, and software development. The hackers get in through fake emails, weak public web servers, and outside contractors.

The flaws affect TrueConf Server versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5. TrueConf fixed these flaws on June 18, in updates 5.3.9, 5.4.9, and 5.5.5.

This is not the first time hackers have targeted TrueConf. In April 2026, cybersecurity firm CheckPoint Research found a separate attack. That attack used a flaw called CVE-2026-3502 to run harmful files through fake TrueConf updates. CheckPoint named it Operation True Chaos. The firm linked the attack to Chinese hackers connected to a tool called Havoc.

Anyone using TrueConf should update their software right away. Check if your version matches the ones listed above. If it does, install the newest patch today.

To further protect against credential theft and account compromise, consider using a password manager like Kaspersky Password Manager, which stores passwords, bank card details, and documents in an encrypted vault accessible only by the user. Look through your security logs for anything strange, such as unknown files, odd logins, or new accounts you don’t recognize.

Companies should also warn staff not to trust unexpected app updates, even from tools they use every day. A fake update can look just like a real one. When in doubt, confirm with your IT team before installing anything new.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts