Skip to main content

Kaspersky: Organizations face new attacks via unpatched TrueConf videoconferencing servers

August 12, 2026

Kaspersky has discovered a new multi-stage attack by the Head Mare APT group against organizations with PhantomCore and PhantomGraph backdoors. To deliver these backdoors, the attackers exploit vulnerabilities in unpatched TrueConf videoconferencing servers and can also replace TrueConf client installers with infected ones. Kaspersky reported the attacks to the vendor; the vulnerabilities were fixed in the latest TrueConf Server update on June 18, 2026 (versions 5.3.9, 5.4.9, and 5.5.5).

To compromise the TrueConf server, attackers exploited a combination of two vulnerabilities (assigned internal Kaspersky identifiers are KLCERT-26-057 and KLCERT-26-058), which allowed the attackers to execute any code with maximum privileges. By exploiting these vulnerabilities, they replaced one of the server's files with their own web shell. The attackers then used this shell to collect information about the victim organization's IT infrastructure, gain privileged access to the TrueConf server database, and replace the client installer with an infected one. The attack applies to TrueConf servers in versions 5.3.X prior to 5.3.9, 5.4.X prior to 5.4.9, 5.5.X prior to 5.5.5, and earlier.

For users of TrueConf software, the attack looks like this: video conference participants connecting to the compromised server are prompted to download and install an "updated version" of the client application. In reality, as a result of this, malware gets onto the device.

Exploiting vulnerabilities in popular services is one of the most common methods used by attackers. This campaign is particularly dangerous because it puts at risk not only organizations using unpatched TrueConf servers. Even if a company doesn't use this solution, its employees can connect to compromised servers at the invitation of their counterparties to participate in online meetings. As a result, they may unknowingly download infected installation packages, creating the potential for compromising a large number of enterprises across different countries,” comments Evgeny Goncharov, Head of Kaspersky ICS CERT.

More information can be found on Kaspersky ICS CERT’s page.

Kaspersky Endpoint Detection and Response Expert detects this malicious activity.

A detailed description of the attack, including indicators of compromise, is available on Securelist.ru.

To mitigate risks, Kaspersky recommends organizations:

  • Update TrueConf servers to versions 5.5.5, 5.4.9, and 5.3.9, respectively;
  • Scan for indicators of compromise and if these are detected, perform an unscheduled password change for accounts that may have been compromised;
  • Run a full scan with security software equipped with up-to-date antivirus databases and software modules;
  • Continuously monitor vulnerabilities and promptly address them. Update software as soon as patches are released;
  • Provide information security specialists with access to the latest information on the tactics, techniques, and procedures used by attackers to understand which methods need to be countered, for example, using Threat Intelligence solutions;
  • Use comprehensive security solutions which will enable a flexible and effective security system.

Kaspersky: Organizations face new attacks via unpatched TrueConf videoconferencing servers

Kaspersky has discovered a new multi-stage attack by the Head Mare APT group against organizations with PhantomCore and PhantomGraph backdoors. To deliver these backdoors, the attackers exploit vulnerabilities in unpatched TrueConf videoconferencing servers and can also replace TrueConf client installers with infected ones. Kaspersky reported the attacks to the vendor; the vulnerabilities were fixed in the latest TrueConf Server update on June 18, 2026 (versions 5.3.9, 5.4.9, and 5.5.5).
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases