bleeping-computer · Crawled Aug 8, 2026
Hackers breach TrueConf to trojanize client installers with backdoors
4 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 4 extracted
MITRE ATT&CK TTPs 14 techniques
T1003.001 LSASS Memory · Credential Access T1059.001 PowerShell · Execution T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1087.001 Local Account · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1135 Network Share Discovery · Discovery T1485 Data Destruction · Impact T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1573 Encrypted Channel · Command And Control T1588 Obtain Capabilities · Resource Development