Tag: klcert 26 057
3 articles

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware
In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

TrueConf Server Flaws Targeted to Deploy PhantomCore Backdoor
Security researchers at Kaspersky have uncovered a sneaky plot by threat actor Head Mare to exploit unpatched TrueConf servers and deploy the PhantomCore backdoor to unsuspecting users. The attack relies on a two-stage vulnerability chain that allows attackers to run malicious commands with high-level privileges.

Hackers Breach TrueConf Servers to Deploy Backdoors via Trojanized Updates
Hackers have breached TrueConf servers by exploiting a gaping security hole - an open TCP port that lets them in without needing a password, then using trojanized updates to deploy backdoors and take control. This sneaky attack vector has been used by threat actors like Head Mare to spread malware and gain unauthorized access.