Summary
- Kaspersky attributes a July campaign to Head Mare, which it says chained two vulnerabilities in unpatched TrueConf Server installations.
- Compromised servers were used to replace legitimate TrueConf client installers with unsigned packages carrying the PhantomCore backdoor.
- Employees can encounter the malicious packages when connecting to compromised TrueConf infrastructure operated by counterparties, extending the incident beyond the original server owner.
Attackers have compromised unpatched TrueConf video-conferencing servers and replaced legitimate client installers with malicious versions, creating a software-distribution route that can reach organisations beyond the original server owner.
Kaspersky said it discovered the campaign in July and attributed the activity to the group it tracks as Head Mare. The attribution remains Kaspersky’s assessment rather than an independently established identity for the operators.
The researchers said the attackers chained two newly identified vulnerabilities, tracked internally as KLCERT-26-057 and KLCERT-26-058. The combination allowed an unauthenticated attacker to connect to a vulnerable TrueConf Server, escape the software’s isolated execution environment, and ultimately run arbitrary code with NT AUTHORITY\SYSTEM privileges.
Kaspersky said vulnerable releases included TrueConf Server 5.3 versions before 5.3.9, 5.4 versions before 5.4.9, 5.5 versions before 5.5.5, and earlier releases. TrueConf issued the fixed versions on 18 June.
After gaining privileged control of a server, the attackers replaced a legitimate server file with a web shell. Kaspersky said that access was then used for infrastructure reconnaissance, privileged access to the TrueConf database, and replacement of the legitimate TrueConf Client distribution with a malicious installer carrying the PhantomCore backdoor.
The company also identified another backdoor it named PhantomGraph on compromised infrastructure. Kaspersky associates both malware families with the Head Mare campaign, but Cyber Insider is omitting operational indicators and command details that do not add to the wider supply chain picture.
The altered client packages did not carry a valid TrueConf digital signature, according to Kaspersky.
The more unusual aspect of the campaign is how software trust moves between organisations. Kaspersky specifically warned that a company does not need to operate a vulnerable TrueConf Server itself to encounter a malicious installer. Employees can connect to a compromised server operated by a counterparty for a meeting and download a replaced client installation package from that external infrastructure.
That changes the incident from a conventional server compromise into a third-party distribution problem. The initial weakness belongs to one organisation’s conferencing server, while the endpoint receiving the malicious software may be operated by a customer, supplier, contractor, or other external participant.
Software-distribution channels are valuable during intrusions because they arrive with existing assumptions about provenance. The attacker does not necessarily need to persuade a user to retrieve an unrelated executable from an obviously suspicious source. A compromised collaboration server can instead provide what appears to be the expected client software.
The missing digital signature provides a distinction between the packages Kaspersky observed and legitimate TrueConf software, but the campaign still raises a wider question about how organisations validate software received through infrastructure controlled by counterparties rather than through a vendor’s central distribution channel.
Kaspersky said it is observing several active Head Mare campaigns against Russian organisations in sectors including instrumentation, electronics, transport, energy, IT, and software development. The group has used several access methods across those campaigns, including phishing, exploitation of public-facing systems, and access through contractors.
The two TrueConf vulnerabilities were already patched before the July campaign was discovered. That places part of the exposure on infrastructure that remained behind the current server releases, but patching the compromised server does not necessarily resolve the downstream impact.
Organisations that downloaded software from an affected counterparty may still have an endpoint investigation after the original server has been restored. That separation between the primary compromise and the downstream recipient is what gives the TrueConf campaign its supply chain character.


