Kaspersky discovered in July that Head Mare used TCP port 4307, which is open by default, to connect to TrueConf servers without authentication — then leveraged unpatched flaws to deliver backdoors via trojanized installers.
How Head Mare gains control
According to Kaspersky’s analysis, the intrusion begins against unpatched TrueConf Server instances running older releases of the product. The attacker connects over TCP port 4307 and exploits two vulnerabilities tracked by Kaspersky as KLCERT-26-057 and KLCERT-26-058. The first allows execution of a malicious script inside TrueConf’s isolated environment; the second permits escape from that sandbox to run commands on the underlying operating system.
From there the adversary elevates privileges to NT AUTHORITY\SYSTEM and replaces the file \public\js\locale.php with a web shell. Kaspersky reports the actor uses that web shell for persistent remote access, to collect information from the victim environment, and to access the TrueConf database — actions that enable the next stage of the compromise: replacing legitimate installers with malicious versions.
PhantomCore and PhantomGraph: trojanized installers and OneDrive command-and-control
Head Mare replaces the legitimate TrueConf Client installer hosted on the compromised server with a trojanized, non‑digitally signed installer containing the PhantomCore backdoor. When members of an organization connect to their local TrueConf server, they receive the update and the malicious client.
Separately, Kaspersky observed deployment of PhantomGraph, a backdoor composed of two DLLs named SysExcSvc.dll and SysReadSvc.dll. PhantomGraph accepts commands via a Microsoft OneDrive account, executes those commands, and returns results through that channel. Observed activities using PhantomGraph included dumping the memory of the Local Security Authority Subsystem Service (LSASS) process to exfiltrate credentials, running reconnaissance commands such as hostname and whoami, and starting a reverse SSH tunnel.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTrueConf vulnerabilities, affected versions, and vendor fixes
The flaws exploited by Head Mare affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions. The vendor released fixes in versions 5.3.9, 5.4.9, and 5.5.5 on June 18.
Separately, CheckPoint Research reported in April 2026 that threat actors were abusing a zero‑day arbitrary file execution flaw in TrueConf tracked as CVE‑2026‑3502 to deliver trojanized client updates. CheckPoint called that campaign “Operation True Chaos” and tentatively attributed it to Chinese threat actors using the Havoc implant. Kaspersky’s July findings describe a different exploitation chain but echo the operational risk of trojanized TrueConf client installers.
Targets, access methods, and operational impact
Kaspersky says it is currently observing multiple active Head Mare campaigns that target Russian organizations across a range of sectors: instrumentation, electronics, transportation, energy, IT, and software development. The actor’s initial access methods include phishing, exploitation of public‑facing web servers, and access via contractors.
Kaspersky also warns of a specific second‑order risk: “Even if your organization does not use the TrueConf server, employees of the organization can connect to compromised counterparty TrueConf servers to participate in online meetings and download infected installation packages.” In other words, compromise can spread via trusted meeting links and partner infrastructure, not only via an organization’s own servers.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: Prioritize patching TrueConf Server instances to versions 5.3.9, 5.4.9, or 5.5.5 or later; hunt for replaced files such as \public\js\locale.php and for non‑digitally signed TrueConf Client installers being served from internal servers. Look for OneDrive traffic patterns and unusual LSASS memory dumps that match PhantomGraph behavior.
- Procurement and enterprise IT leaders: Revisit deployment models that rely on on‑premise update chains and ensure digital signing and integrity checks are enforced for client installers; evaluate counterparty risk from partners and suppliers who might host compromised TrueConf servers.
- End users and contractors: Be wary of automatic TrueConf client updates received when joining external meetings; report unexpected installer prompts and avoid running unsigned installers received through conferencing links.
Kaspersky’s report ties a methodical exploitation chain — unauthenticated access via TCP port 4307, sandbox escape, SYSTEM privilege escalation, web shell persistence, and trojanized client updates — to active campaigns that continue to target organizations in Russia’s enterprise and government space. The vendor patches issued on June 18 address the specific flaws Kaspersky observed; the remaining questions are operational: how many servers remain unpatched, how many client installers were redistributed inside affected environments, and whether secondary compromises using stolen credentials will expand the campaign’s reach.




