Malware

PhantomCore

According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare. It has been active since 2023 and is known for consistently targeting Russia. PhantomCore collects the victim’s information, including the public IP address, to gain detailed insights into the target before deploying the final-stage payload or executing additional commands on the compromised system. PhantomCore is known to deploy ransomware payloads such as LockBit and Babuk, inflicting significant damage on the victim’s systems.

Indicators of Compromise 39

MITRE ATT&CK TTPs 14

Source Articles

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
In July 2026, the APT group Head Mare exploited two previously unknown vulnerabilities in unpatched TrueConf servers (versions 5.3.x through 5.5.5) to gain SYSTEM-level access and deploy web shells. The attackers replaced legitimate TrueConf client installers with malicious versions containing the PhantomCore backdoor, which was used to compromise video conference participants. A second backdoor, PhantomGraph, composed of SysExcSvc.dll and SysReadSvc.dll, was also deployed to establish persistence and execute commands via Base64-encoded PowerShell scripts. The group targeted Russian organizations across multiple sectors, using compromised servers and phishing to distribute malware. Kaspersky has detected the activity and provided indicators and detection rules.
securelist ·3w ago
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor Head Mare has exploited vulnerabilities in unpatched TrueConf servers to replace legitimate client installers with malicious versions delivering the PhantomCore backdoor and RAT. The attack chain involves exploiting two vulnerabilities, KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution with SYSTEM privileges, deploy a web shell, and substitute legitimate installers. The attackers also deploy a secondary backdoor, PhantomGraph, composed of two DLLs that exfiltrate data via Microsoft OneDrive and establish persistence through PowerShell commands.
hacker-news ·3w ago
Hackers breach TrueConf to trojanize client installers with backdoors
The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.
bleeping-computer ·3w ago