Threat Intelligence

Hacktivist group Head Mare exploits TrueConf vulnerabilities to deliver backdoors

The hacktivist group Head Mare has been exploiting unpatched vulnerabilities in TrueConf video conferencing servers to distribute malicious versions of client installers that deliver backdoors, Bleeping Computer reports.

The attackers leverage vulnerabilities, tracked as KLCERT-26-057 and KLCERT-26-058, to execute arbitrary code and gain elevated privileges on the server, according to Kaspersky. They then replace the legitimate client installer with a trojanized version containing the PhantomCore backdoor. This allows them to infect other users who update their TrueConf client. Additionally, Head Mare deploys PhantomGraph, a separate backdoor that operates via a OneDrive account.

The group is actively targeting Russian organizations across various sectors, including instrumentation, electronics, transportation, energy, IT, and software development. Initial access methods observed include phishing, exploiting public-facing web servers, and contractor access. TrueConf has released patches for the exploited vulnerabilities in versions 5.3.9, 5.4.9, and 5.5.5.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds