CYBERSECURITYTRACKER
TRACKING7,631 stories in this site build1,635 vulnerability news stories in this site build
Permanent story citation

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4134

As cited

Copy frozen at (site build).

vulnerabilities

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Kaspersky detected attacks in July 2026 where the threat actor Head Mare exploited security vulnerabilities in unpatched TrueConf servers to deliver PhantomCore malware. The campaign targeted Russian companies across multiple sectors including energy, transport, electronics, and software development. Exploitation involved a vulnerability chain in the videoconferencing platform.

Why it matters: Organizations running TrueConf servers face immediate risk of malware installation and installer compromise; patching unpatched instances and reviewing TrueConf deployments is critical for companies in targeted sectors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary