Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
The Head Mare APT group is exploiting multiple vulnerabilities in TrueConf servers to deliver the PhantomCore and PhantomGraph backdoors. Attackers connect to TrueConf servers without authorization, call a server function to transmit a malicious script, and then use a web shell to steal data, gain privileged access to the database, and replace the TrueConf client installer with a compromised version containing the backdoors. The group uses a combination of phishing, exploiting public web servers, and subcontractor methods to distribute their backdoors. Kaspersky has identified several indicators of compromise, including specific files, registry keys, and YARA rules to detect the activity.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
