Malware
PhantomCore
According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare. It has been active since 2023 and is known for consistently targeting Russia. PhantomCore collects the victim’s information, including the public IP address, to gain detailed insights into the target before deploying the final-stage payload or executing additional commands on the compromised system. PhantomCore is known to deploy ransomware payloads such as LockBit and Babuk, inflicting significant damage on the victim’s systems.
Indicators of Compromise 39
Domain bright-deals[.]site Domain mirrors[.]ustc[.]edu[.]cn Domain nova-stream[.]site Domain penzadogshelter[.]site Domain rinomobile[.]ink Domain sina[.]com Domain trendy-market[.]site Filename SysExcSvc.dll Filename SysReadSvc.dll Filename \public\js\locale.php Filename itcsrvup64.exe Filename locale.php Filename wtsapi32.dll MD5 0e4541c3153ec5ed01497f19cf4f63d0 MD5 0e79996d9483d1e44fea32b0a48c2c19 MD5 129462164a7d52e9ea8560b60f0412c5 MD5 12d4e8f5295f2ef7e0f9bfc0f4830939 MD5 2bb75c20e778eb5c416965bd4d4259b1 MD5 43f435c3c437bc879a2d7d4634f43494 MD5 489f43be558b2679284ceabed7adc4f3 MD5 4d27b4eb1c5dbb3d8160f29b8119523e MD5 748c9f8cb1065000616204935f96207f MD5 7f267006cac10f341c356b62fe493527 MD5 8fcc3e4ccbf1725d9989fb464abf3561 MD5 aee9642b45b099cb7f3053b9b680b425 MD5 b348642146ea34771e5785c5857950f5 MD5 b3a6fee3307f1c26841fd5c60f04b013 MD5 c3a2abe8756910f42582b04a44ea3514 MD5 c5a460e4e68a088f6e51b2c6474642ec MD5 c915cb6c2aeb863ee8479238e1644217 MD5 dd1fd2b459b97b7d59375cb8383cd19a MD5 ec0bf4a2186a88874e9f26f07cfeb532 MD5 ee2861d5965e8730708cd1da8a93fa4c IP 194[.]87[.]239[.]71 IP 194[.]87[.]93[.]153 IP 31[.]59[.]102[.]61 IP 38[.]244[.]205[.]244 IP 81[.]177[.]32[.]12 IP TCP port 4307
MITRE ATT&CK TTPs 14
T1003.001 T1059.001 T1078 T1078.001 T1087.001 T1090 T1105 T1129 T1135 T1485 T1566 T1571 T1573 T1588
LSASS Memory
Credential Access
PowerShell
Execution
Valid Accounts
Defense Evasion
Default Accounts
Defense Evasion
Local Account
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Shared Modules
Execution
Network Share Discovery
Discovery
Data Destruction
Impact
Phishing
Initial Access
Non-Standard Port
Command And Control
Encrypted Channel
Command And Control
Obtain Capabilities
Resource Development
Source Articles
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
In July 2026, the APT group Head Mare exploited two previously unknown vulnerabilities in unpatched TrueConf servers (versions 5.3.x through 5.5.5) to gain SYSTEM-level access and deploy web shells. The attackers replaced legitimate TrueConf client installers with malicious versions containing the PhantomCore backdoor, which was used to compromise video conference participants. A second backdoor, PhantomGraph, composed of SysExcSvc.dll and SysReadSvc.dll, was also deployed to establish persistence and execute commands via Base64-encoded PowerShell scripts. The group targeted Russian organizations across multiple sectors, using compromised servers and phishing to distribute malware. Kaspersky has detected the activity and provided indicators and detection rules.
securelist ·3w ago
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor Head Mare has exploited vulnerabilities in unpatched TrueConf servers to replace legitimate client installers with malicious versions delivering the PhantomCore backdoor and RAT. The attack chain involves exploiting two vulnerabilities, KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution with SYSTEM privileges, deploy a web shell, and substitute legitimate installers. The attackers also deploy a secondary backdoor, PhantomGraph, composed of two DLLs that exfiltrate data via Microsoft OneDrive and establish persistence through PowerShell commands.
hacker-news ·3w ago
Hackers breach TrueConf to trojanize client installers with backdoors
The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.
bleeping-computer ·3w ago