TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related tool (PhantomGraph). The attacks, ongoing since at least May 2026, are aimed at Russian companies across various sectors, including instrumentation, electronics, transport, energy, IT, and software development. The group has also been using fake ViPNet updates to deploy a Rust implant (HelloBackdoor) and a proxy tool (HelloProxy) to deliver malicious payloads and maintain a persistent presence on compromised systems.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
