Hackers Exploit Unpatched TrueConf Servers to Deliver Malicious Installers
Cybersecurity researchers have uncovered a new wave of attacks by the threat actor known as Head Mare, which is exploiting security flaws in unpatched TrueConf servers. TrueConf is a video conferencing platform used by organisations for internal communications. According to Kaspersky, which detected the campaign in July 2026, the attacks have targeted Russian companies across the instrumentation, electronics, transport, energy, IT, and software development sectors.
The attackers exploit a chain of vulnerabilities in unpatched TrueConf servers to replace legitimate client installers with malicious versions, allowing them to deploy malware referred to as PhantomCore onto victim systems. By tampering with trusted installer files, attackers can trick users into unknowingly installing malware while believing they are downloading a genuine update or client from their organisation's own conferencing platform.
While this specific campaign has focused on Russian organisations, the underlying tactic—compromising trusted internal software distribution points to spread malware—is a technique that can be used against any business running outdated or unpatched collaboration and communication software, regardless of location.