12 August 2026
Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participants
Threat Alert
General information about the attack
While investigating an attack on Russian organizations, Kaspersky experts discovered that client installers for the TrueConf video conferencing and corporate communications platform were installing PhantomCore malware in addition to their standard functionality. PhantomCore malware is typically associated with the activity of the Head Mare APT group. The malicious installers were downloaded from a TrueConf server belonging to the attacked organization.
Research into the compromised server revealed that attackers use a combination of two vulnerabilities (assigned internal Kaspersky identifiers KLCERT-26-057 and KLCERT-26-058) to execute arbitrary code. This enables them to replace one of the TrueConf server files with their own web shell. This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database, and replace the legitimate client installers mentioned earlier.
On *nix servers running TrueConf, the attackers install a backdoor that hides its files and, by intercepting TrueConf network functions, listens for commands sent from the attackers via the TrueConf protocol. Furthermore, on *nix systems, the attackers install a backdoor that uses GitHub as a command and control channel.
The manufacturer addressed the vulnerabilities used by the attackers in the latest TrueConf server update (versions 5.3.9, 5.4.9, and 5.5.5), released on June 18, 2026. We are currently coordinating with the vendor’s representatives to notify users and mitigate the consequences of the attack. The vendor continues to notify TrueConf system administrators of the need for immediate updates as soon as the relevant versions are released.
This document is intended to alert both TrueConf server owners, as well as organizations whose employees have participated in video conferences using TrueConf and may have downloaded malware as part of the client application installation packages.
To reduce the risk of security incidents, we recommend taking the measures outlined in this document as soon as possible.
For more information, please contact us at ics-cert@kaspersky.com.
Technical details
An unauthorized attacker can connect to TrueConf server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5, as well as earlier versions (our internal analysis showed that all TrueConf server versions released since 2022 are vulnerable) via port 4307/TCP (open by default, according to TrueConf documentation) and execute a malicious script on the server by calling an undocumented function. The internal identifier KLCERT-26-057 has been assigned to track this vulnerability.
The uploaded malicious script is executed in an isolated environment, where potentially hazardous libraries (io, os, etc.) are unavailable. However, attackers can exploit another vulnerability (assigned internal Kaspersky identifier KLCERT-26-058) to execute arbitrary code on the server with NT AUTHORITY\SYSTEM privileges. This enables them to replace the file C:/Program Files/TrueConf Server/httpconf/site/public/js/locale.php with a malicious web shell program, as well as delete records from the TrueConf event logs related to the exploit’s operation.
Attackers use the web shell to install a backdoor-type malicious program on the server that consists of two components:
- A communication module that receives commands from the attackers and transmits the results of their execution. The attackers use a Microsoft OneDrive cloud storage account as the command and control (C&C) server.
- An execution module that reads commands passed by the first module, executes them, and saves the result.
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc. The attackers install this malware as a backup command and control channel because all subsequent actions are carried out by remotely running PowerShell scripts via a web shell. A detailed analysis of the malware and the attackers’ actions will be presented on the Kaspersky Threat Intelligence Portal in a separate report on this series of attacks.
Most importantly, during the attack, the attackers replace the TrueConf client distribution file located at C:\Program Files\TrueConf Server\ClientInstFiles\trueconf_windows_client_x64.exe. After that, all conference participants with x64-based systems receive a message stating that they need to download a new version of the TrueConf client.
Important! Even if your organization does not use a TrueConf server, your employees may connect to compromised TrueConf servers of contractors to participate in online meetings and download infected installation packages.

According to the research, after launching on a workstation, the infected installer deploys the TrueConf client on the system, but also unpacks the PhantomCore malware to the path %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll.
This malware enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system. To automatically launch the malware after system startup, a registry key is created: HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32, with the value pointing to the malicious executable file.
A detailed description of the malware will also be presented in a report on the analyzed series of attacks.
Recommendations
- For TrueConf server owners: update the server to versions 5.3.9, 5.4.9 or 5.5.5.
- Conduct a scan for indicators of compromise.
- Perform a full check with antivirus software that has up-to-date antivirus databases and modules.
- In the event that any indicators of compromise are detected, change the passwords for all potentially affected accounts and contact us at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.
Indicators of compromise
Note: The indicators provided in this section were valid and up-to-date at the time of publication.
File hashes (MD5)
4d27b4eb1c5dbb3d8160f29b8119523e – web shell locale.php
748c9f8cb1065000616204935f96207f – malicious installer trueconf_windows_update.exe
c5a460e4e68a088f6e51b2c6474642ec – PhantomCore backdoor
129462164a7d52e9ea8560b60f0412c5 – doc.txt
ec0bf4a2186a88874e9f26f07cfeb532 – usocacheddata.txt
b348642146ea34771e5785c5857950f5
c915cb6c2aeb863ee8479238e1644217 – doc.txt
0e79996d9483d1e44fea32b0a48c2c19 – doc.txt
2bb75c20e778eb5c416965bd4d4259b1 – trueconf_windows_client_x64_[redacted].exe
b3a6fee3307f1c26841fd5c603e2b013 – usocacheddata.txt
8fcc3e4ccbf1725d9989fb464abf3561 – usocacheddata.txt
489f43be558b2679284ceabed7adc4f3 – PhantomGraph backdoor
0e4541c3153ec5ed01497f19cf4f63d0 – PhantomGraph backdoor
12d4e8f5295f2ef7e0f9bfc0f4830939 – PhantomGraph backdoor
7f267006cac10f341c356b62fe493527 – PhantomGraph backdoor
ee2861d5965e8730708cd1da8a93fa4c – PhantomGraph backdoor
dd1fd2b459b97b7d59375cb8383cd19a – PhantomGraph backdoor
4333f52668996c0fa44c14fefba7fecc – Linux backdoor
c3a2abe8756910f42582b04a44ea3514 – Linux backdoor
43f435c3c437bc879a2d7d4634f43494 – Linux backdoor
aee9642b45b099cb7f3053b9b680b425 – rootkit/backdoor
File paths
C:\Windows\System32\inetsrv\SysExcSvc.dll
C:\Windows\System32\inetsrv\SysReadSvc.dll
C:\Windows\System32\inetsrv\graphi-refresh.dat
C:\Windows\System32\inetsrv\share\input_*.txt
C:\Windows\System32\inetsrv\share\output_*.txt
%TEMP%\cmd_cmd_*.bat
%LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll
/etc/systemd/system/omicluster.service
/etc/systemd/system/schedul2-bin.service
/opt/acronis/bin/schedul2-bin
/omi/bin/omicluster
/usr/lib64/libzvbi-tchain.so.2
/var/tmp/cx2
IP addresses and domain names
81.177.32[.]12
194.87.239[.]71
194.87.93[.]153
38.244.205[.]244
31.59.102[.]61
penzadogshelter[.]site
trendy-market[.]site
bright-deals[.]site
nova-stream[.]site
rinomobile[.]ink
urbanpixel[.]store
flexish[.]shop
media-hub[.]today
cosmetic-deals[.]store
vks.gossopka[.]forum
Windows service names
SysExcSvc
SysReadSvc
Registry keys
HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32
Security solutions verdicts
Backdoor.PHP.WebShell.abi
Backdoor.Win64.PhantomCore.dt
Trojan.Win64.Agent.smgvnc
HEUR:Backdoor.Win64.PhantomCore.gen
HEUR:Backdoor.Linux.Agent.fb
Trojan.Win64.PhantomGraph.gen
Trojan.Win64.Agent.smgvnb
UDS:Backdoor.Win64.PhantomCore.a
YARA rules import "pe"
rule apt_HeadMare_PhantomCore
{
meta:
description = "Rule to detect PhantomCore used by HeadMare"
author = "Kaspersky"
copyright = "Kaspersky"
version = "1.0"
last_modified = "2026-08-02"
hash = "c5a460e4e68a088f6e51b2c6474642ec"
strings:
$a1 = "lying.dll" ascii
$a2 = { 2D 7F 95 4C 2D F4 51 58 }
$a3 = { 4F 81 67 F7 7E 7B 05 14 }
condition:
(uint16(0) == 0x5A4D) and (filesize > 4MB) and (filesize < 12MB) and (all of them)
and pe.exports("DllGetClassObject") and pe.exports("DllCanUnloadNow") and (pe.number_of_signatures == 0)
and (for any i in (0 .. pe.number_of_sections - 1) : (pe.sections[i].name == ".gxfg"))
and (for any i in (0 .. pe.number_of_sections - 1) : (pe.sections[i].name == ".tls"))
}
rule apt_HeadMare_FakeConf_installer
{
meta:
description = "Rule to detect any unsigned TrueConf installers"
author = "Kaspersky"
copyright = "Kaspersky"
version = "1.0"
last_modified = "2026-08-02"
hash = "748c9f8cb1065000616204935f96207f"
strings: $a1 = "TrueConf Setup" wide $a2 = "This installation was built with Inno Setup." wide
condition: (uint16(0) == 0x5A4D) and (filesize > 20MB) and (all of them) and (pe.number_of_signatures == 0) }
rule apt_HeadMare_PhantomCore_exchange
{
meta:
description = "Rule to detect PhantomCore exchange module used by HeadMare"
author = "Kaspersky"
copyright = "Kaspersky"
version = "1.0"
last_modified = "2026-08-02"
hash = "489f43be558b2679284ceabed7adc4f3"
strings: $a1 = "graphi_exchange.dll" ascii $a2 = "graphi-client/1.0" ascii
$b1 = "https://graph.microsoft.com/v1.0/me/drive/root:/" ascii $b2 = ":/children?$select=name,id&$top=200" ascii $b3 = "offline_access Files.ReadWrite" ascii $b4 = "GRAPHI_INSECURE" ascii $b5 = "\"@microsoft.graph.conflictBehavior\":\"replace\"}" ascii $b6 = "https://login.microsoftonline.com/" ascii
condition: (uint16(0) == 0x5A4D) and (any of ($a*)) and (3 of ($b*)) }
rule apt_HeadMare_PhantomCore_executor
{
meta:
description = "Rule to detect PhantomCore executor module used by HeadMare"
author = "Kaspersky"
copyright = "Kaspersky"
version = "1.0"
last_modified = "2026-08-02"
hash = "dd1fd2b459b97b7d59375cb8383cd19a"
strings: $a1 = "graphi_reader.dll" ascii $a2 = "^input_(.+)\\.txt$" ascii
$b1 = "output_" ascii $b2 = "cmd_cmd_" ascii $b3 = "cmd /c \"\"" ascii $b4 = "error: failed to start cmd process" ascii $b5 = "share" ascii $b6 = "SysReadSvc" ascii
condition: (uint16(0) == 0x5A4D) and (filesize < 4MB) and (any of ($a*)) and (4 of ($b*)) }
rule apt_HeadMare_FakeLocale_webshell
{
meta:
description = "Rule to detect the HeadMare TrueConf web shell"
author = "Kaspersky"
copyright = "Kaspersky"
version = "1.0"
last_modified = "2026-08-04"
hash = "4d27b4eb1c5dbb3d8160f29b8119523e"
strings: $a1 = "X-Redirect-Bit" ascii wide nocase $a2 = "tc_vcs_web_db_conn" ascii wide $a3 = "user=postgres" ascii wide
$b1 = "UPL ok::" ascii wide $b2 = "DWN fail nexs" ascii wide $b3 = "DWN fail inv" ascii wide
condition: (2 of ($a*)) or (2 of ($b*)) }
rule apt_HeadMare_TrueConf_Rootkit
{
meta:
description = "Rule to detect the HeadMare rootkit installed on TrueConf servers"
author = "Kaspersky"
copyright = "Kaspersky"
version = "1.0"
last_modified = "2026-08-06"
hash = "aee9642b45b099cb7f3053b9b680b425"
strings: $a1 = "PQconnectdb" $a2 = "obfuscated_data" $a3 = "install_hook"
condition: (uint32(0) == 0x464c457f) and (filesize < 400000) and (all of them) }
rule apt_HeadMare_Github_Backdoor
{
meta:
description = "Rule to detect the HeadMare backdoor with Github C2"
author = "Kaspersky"
copyright = "Kaspersky"
version = "1.0"
last_modified = "2026-08-06"
hash = "43f435c3c437bc879a2d7d4634f43494"
hash = "c3a2abe8756910f42582b04a44ea3514"
strings: $a1 = "cryptor5crypt" $a2 = "execraw_task" $a3 = "jitter_task" $a4 = "upload_task" $a5 = "exec_task" $a6 = "react_comment"
condition: (uint32(0) == 0x464c457f) and (filesize > 5000000) and (filesize < 10000000) and (4 of them) }