Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoors — Threadlinqs Intelligence
As of 2026-08-11, Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoors is a critical-severity apt threat attributed to Head Mare, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1982 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: Head Mare · ESPIONAGE
Kaspersky (Securelist) reports that in July 2026 the Head Mare group, recently reclassified from hacktivist to APT, chained two unauthenticated vulnerabilities (KLCERT-26-057, KLCERT-26-058) in
In July 2026, Kaspersky's Securelist detected in-the-wild exploitation of two vulnerabilities in TrueConf Server, an on-premises video-conferencing platform, by the Head Mare group -- a cluster Kaspersky has now reclassified from hacktivist to advanced persistent threat based on the sophistication of its tradecraft. The attack chain began with an unauthenticated connection to TCP/4307, open by default on vulnerable TrueConf Server builds (versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5). KLCERT-26-057 allowed the attacker to transmit and execute a malicious script inside TrueConf's isolated execution environment; KLCERT-26-058 then let that script escape the sandbox and run arbitrary OS-level commands, escalating to NT AUTHORITY\SYSTEM. TrueConf shipped patches for both flaws on June 18, 2026 (5.3.9, 5.4.9, 5.5.5), but the attacks Kaspersky observed occurred against servers that had not applied them.
With SYSTEM-level access, the operators replaced '...\public\js\locale.php' with a PHP web shell (MD5 4d27b4eb1c5dbb3d8160f29b8119523e) for persistent remote access, then used that access to enumerate the server's infrastructure, escalate privileges inside the TrueConf database, and replace the legitimate TrueConf Client installer with a trojanized build carrying the PhantomCore backdoor. Because the malicious installer lacks TrueConf's valid code-signing signature, organizations that update their clients from a compromised server -- including third-party or partner TrueConf servers -- are exposed even if their own infrastructure is patched, turning the compromise into a software-supply-chain-style distribution vector. PhantomCore is a Windows backdoor that persists via a COM-hijacking registry key under HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32.
Alongside PhantomCore, the operators deployed PhantomGraph, a modular Windows backdoor split across two DLLs -- SysExcSvc.dll (receives operator commands and returns results) and SysReadSvc.dll (executes the commands, largely via dropped batch files) -- installed as Windows services (SysExcSvc/SysReadSvc) through Base64-encoded PowerShell one-liners, and staged under C:\Windows\System32\inetsrv\. PhantomGraph's command-and-control channel rides Microsoft OneDrive cloud-storage accounts rather than a dedicated C2 server, and the operators separately established SSH reverse tunnels for interactive access. Post-exploitation activity included dumping LSASS process memory for credential theft and basic host/user reconnaissance (hostname, whoami). Kaspersky's telemetry also ties the intrusion set to Linux ELF backdoors and a rootkit, indicating a cross-platform toolkit rather than a Windows-only operation.
Head Mare has targeted TrueConf infrastructure before: per The Hacker News, the group exploited a separate set of TrueConf vulnerabilities (BDU:2025-10114, BDU:2025-10115, BDU-2025-10116) to deliver PHP web shells beginning around September 2025, with that campaign publicly disclosed in April 2026. Targeting in the current campaign is confined to Russian organizations across instrument manufacturing, electronics, transportation, energy, IT, and software development -- sectors consistent with espionage-oriented rather than financially or ideologically motivated intrusion activity, notwithstanding the group's hacktivist origin.
Target sectors: instrument manufacturing, electronics, transport, energy, information technology, software development
Target regions: russia
Timeline
- Head Mare begins exploiting an earlier, separate set of TrueConf vulnerabilities (BDU:2025-10114, BDU:2025-10115, BDU-2025-10116) to deliver PHP web shells, per The Hacker News.
- Head Mare's earlier TrueConf-targeting campaign (BDU:2025-10114/10115/10116) is publicly disclosed.
- TrueConf releases patches for KLCERT-26-057 and KLCERT-26-058 in TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5.
- Head Mare exploits unpatched TrueConf Server instances via unauthenticated access to TCP/4307, chaining KLCERT-26-057 and KLCERT-26-058 to obtain NT AUTHORITY\SYSTEM access.
- Operators replace '...\public\js\locale.php' with a PHP web shell (MD5 4d27b4eb1c5dbb3d8160f29b8119523e) to maintain persistent remote access to the compromised TrueConf server.
- The legitimate TrueConf Client installer is replaced with an unsigned, trojanized build carrying the PhantomCore backdoor, exposing users who update from the compromised server.
- The dual-module PhantomGraph backdoor (SysExcSvc.dll/SysReadSvc.dll) is installed as Windows services via Base64-encoded PowerShell commands, using Microsoft OneDrive accounts for command-and-control.
- Operators dump LSASS process memory for credential theft, perform host/user reconnaissance (hostname, whoami), and establish SSH reverse tunnels for interactive access.
- Kaspersky Securelist publishes a detailed report on the Head Mare TrueConf campaign, including IOCs and detection guidance.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1190, T1195.002, T1059.001, T1059.003, T1569.002, T1546.015, T1543.003, T1140, T1036.005, T1003.001