Russian cybersecurity firm Kaspersky disclosed a targeted supply-chain campaign in July 2026 involving the hacktivist group Head Mare, which infected legitimate installations of TrueConf communication software with malicious backdoors. According to Kaspersky researchers, the attackers exploited server vulnerabilities to substitute legitimate client installers with trojanized variants carrying the PhantomCore and PhantomGraph payloads, granting unauthorized access to targeted organizational systems.
Attack Chain and Server Compromise Details
The multi-stage compromise begins when attackers target port 4307/TCP on vulnerable infrastructure, according to Kaspersky’s technical breakdown. By exploiting specific server flaws, the hackers execute a sandbox-escape technique that lets them break out of isolated execution environments. Following this escape, the actors deploy a web shell to elevate their privileges to SYSTEM level on the target servers.
With these elevated permissions, Head Mare swaps standard TrueConf client installation packages with modified files. When users download and run these compromised installers, the PhantomCore and PhantomGraph backdoors deploy silently onto the endpoint devices. Kaspersky identified two specific server vulnerabilities exploited as entry points in this campaign, tracked under identifiers KLCERT-26-057 and KLCERT-26-058.
PhantomGraph and Cloud-Based C2 Communications
PhantomGraph relies on Microsoft OneDrive for its command-and-control (C2) communications, according to security analysts. By leveraging a trusted cloud storage provider, the malware blends its traffic with legitimate network activity to evade detection by enterprise security tools. This technique allows the threat actors to mask their operational infrastructure behind standard corporate data flows.
The campaign primarily targets Russian organizations operating in strategically vital sectors, including electronics, instrumentation, energy, transport, and IT software development. Kaspersky published indicators of compromise (IoCs), including MD5 file hashes and attacker-controlled domains, urging network administrators in impacted industries to scan their environments for signs of intrusion.
Affected Software Versions and Patch Availability
TrueConf issued patches on June 18, 2026, to address the server vulnerabilities exploited in the Head Mare campaign. According to the company’s security advisory, the affected software iterations include:
- TrueConf Server versions 5.3.x prior to version 5.3.9
- TrueConf Server versions 5.4.x prior to version 5.4.9
- TrueConf Server versions 5.5.x prior to version 5.5.5
Administrators running vulnerable instances must update their servers immediately to prevent file substitution attacks. Organizations should cross-reference their endpoint logs against the published IoCs to verify whether unauthorized installers were deployed prior to patch implementation.