← Back to articles
Hackers breach TrueConf to trojanize client installers with backdoors
Cybersecurity·11 May 2025·8 min read

Hackers breach TrueConf to trojanize client installers with backdoors

Information
  
TrueConf Server is a software solution for video conferencing and enterprise communication. It supports on-premises deployment, serving as a central server for managing meetings, voice and video communication, messaging, screen sharing, and user management through the TrueConf Client. It also supports integration with other communication systems and enterprise infrastructure.

Incident

  The Head Mare hacking group was found to have exploited vulnerabilities in unpatched TrueConf Server versions to gain remote access to the systems and deploy backdoors on the servers. The vulnerabilities involved are KLCERT-26-057 and KLCERT-26-058.

  An attacker can connect to TCP Port 4307, which is enabled by default without authentication, and then exploit the vulnerability to execute code within TrueConf Server and escape the sandbox to gain access to the server's operating system, before escalating privileges to NT AUTHORITY\SYSTEM. After compromising the machine, the attacker installed a web shell to maintain system persistence and modified TrueConf Server files, including the TrueConf Client Installer provided for user downloads. This causes users who download or install the client from the compromised server to potentially receive an installer embedded with the PhantomCore Backdoor. Furthermore, the attacker installed the PhantomGraph Backdoor, which is capable of receiving remote commands, executing commands on the compromised machine, stealing sensitive data such as credentials from the LSASS process memory, conducting internal system reconnaissance, and establishing a reverse SSH tunnel.

  Kaspersky stated that such attacks have been observed since July 2026, targeting organizations across multiple sectors, such as Instrumentation, Electronics, Transportation, Energy, IT, and Software Development.

Affected Products

•TrueConf Server 5.3.x prior to version 5.3.9

•TrueConf Server 5.4.x prior to version 5.4.9

•TrueConf Server 5.5.x prior to version 5.5.5

Recommendation

  System administrators should verify the installed version of TrueConf Server and upgrade to a patched version, such as 5.3.9, 5.4.9, or 5.5.5. In addition, administrators should review connections to TCP Port 4307, inspect files and Client Installers hosted by the TrueConf Server, and monitor for any suspicious activity associated with the PhantomCore and PhantomGraph backdoors, particularly if the system has previously been exposed to external networks.

References

https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/

https://trueconf.com/blog/update/trueconf-server-security-updates-june-2026?utm_source

https://trueconf.com/docs/server/en/?utm_source

https://trueconf.ru/blog/update/security-updates?utm_source