Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
ID: 049e4452-5bdd-50cb-98b3-d35b0e1c915d
STIX ID: report--049e4452-5bdd-50cb-98b3-d35b0e1c915d
Feed Name: GBHackers
Head Mare APT exploited two unauthenticated TrueConf Server vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to install a malicious web shell on compromised servers, replace legitimate TrueConf client installers with trojanized versions delivering the PhantomCore remote-access backdoor, and deploy additional Windows and Linux backdoors (including GitHub-based C2). The report includes affected TrueConf versions, persistence and privilege-escalation details, file/service/registry IOCs, network infrastructure and domains, and remediation guidance including patches (TrueConf 5.3.9 / 5.4.9 / 5.5.5), AV scans, credential resets, and IOC hunts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
