logo

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks

ID: bfa431f0-bb74-509f-bc2c-5a4521392495

STIX ID: report--bfa431f0-bb74-509f-bc2c-5a4521392495

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: [email protected] (The Hacker News)

...
...

Positive Technologies attributes active exploitation of a three‑vulnerability chain in TrueConf Server (including a CVSS 9.8 command injection) to the PhantomCore hacktivist group; attackers bypassed authentication, deployed PHP web shells and a range of bespoke and public tools to perform lateral movement, credential harvesting, reconnaissance, and proxying, and have also used phishing lures and archive attachments in follow‑on campaigns. The report also profiles related clusters (e.g., CapFIX, multiple "Werewolf" variants) and describes toolsets and operational TTPs observed against Russian organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.