Threat Intelligence, Vulnerability Management

TrueConf vulnerabilities weaponized in pro-Ukrainian hacktivist attacks against Russia

Flags of Russia and Ukraine. No war. Peace. Relationship between Ukraine and Russia.

Attacks chaining a critical vulnerability and a pair of high-severity flaws impacting the TrueConf video conferencing software have been launched by pro-Ukrainian hacktivist operation PhantomCore to infiltrate Russian networks since September, The Hacker News reports.

Initial targeting of TrueConf servers allowed PhantomCore, also known as UNG0901, Fairy Trickster, Rainbow Hyena, and Head Mare, to facilitate lateral movement and deploy several payloads enabling command execution, persistence, reconnaissance, Veeam Backup & Replication software-related password recovery, credential theft, remote access, and remote host control, according to an analysis from Positive Technologies. Additional findings revealed that PhantomCore has leveraged phishing lures in attacks against Russian firms since the beginning of this year.

"The PhantomCore group is one of the most active groups in the Russian threat landscape. The group targets government and private organizations across a wide range of industries," said researchers. Another Positive Technologies report showed that Russian industrial and aviation entities have been targeted by the financially motivated CapFIX threat group in phishing campaigns involving the impersonation of official government agency communications.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds