Attacks chaining a critical vulnerability and a pair of high-severity flaws impacting the TrueConf video conferencing software have been launched by pro-Ukrainian hacktivist operation PhantomCore to infiltrate Russian networks since September, The Hacker News reports.Initial targeting of TrueConf servers allowed PhantomCore, also known as UNG0901, Fairy Trickster, Rainbow Hyena, and Head Mare, to facilitate lateral movement and deploy several payloads enabling command execution, persistence, reconnaissance, Veeam Backup & Replication software-related password recovery, credential theft, remote access, and remote host control, according to an analysis from Positive Technologies. Additional findings revealed that PhantomCore has leveraged phishing lures in attacks against Russian firms since the beginning of this year."The PhantomCore group is one of the most active groups in the Russian threat landscape. The group targets government and private organizations across a wide range of industries," said researchers. Another Positive Technologies report showed that Russian industrial and aviation entities have been targeted by the financially motivated CapFIX threat group in phishing campaigns involving the impersonation of official government agency communications.
Threat Intelligence, Vulnerability Management
TrueConf vulnerabilities weaponized in pro-Ukrainian hacktivist attacks against Russia
(Image credit: opolja via Getty)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
