"Kaspersky said it detected the attacks in July 2026."
How Head Mare moves from server access to poisoned clients
Security researchers at Kaspersky report that the threat actor known as Head Mare has again exploited unpatched TrueConf servers to push malicious installers to end users. The intrusions target TrueConf Server deployments on the default TCP port 4307 and rely on a two-stage vulnerability chain tracked as KLCERT-26-057 and KLCERT-26-058. According to Kaspersky, attackers first connect to the server on port 4307 and use KLCERT-26-057 to execute a script inside an isolated environment. They then exploit KLCERT-26-058 to escape that environment and run arbitrary commands on the underlying host with NT AUTHORITY\\SYSTEM privileges.
Replacement of installers and the PhantomCore delivery mechanism
Once they have SYSTEM-level command execution, the attackers replace the file "...\public\js\locale.php" with a web shell to maintain persistent remote access. Kaspersky said the web shell has been used to map IT infrastructure, harvest privileged access to the TrueConf database, and substitute the original TrueConf Client distribution with an infected version that installs the PhantomCore backdoor and remote access trojan (RAT). The intrusion sequence — initial exploit, sandbox escape, SYSTEM execution, web shell deployment, reconnaissance, and installer replacement — allows the adversary to weaponize a widely distributed client package as a mass-delivery vector.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePhantomGraph, OneDrive C2, and in‑memory tactics
Kaspersky additionally identified a related backdoor family they call PhantomGraph, which shares code overlap with PhantomCore. PhantomGraph is composed of two DLL modules: "SysExcSvc.dll," which receives commands and exfiltrates results to Microsoft OneDrive used as command-and-control (C2), and "SysReadSvc.dll," which parses and executes those commands and stores the results. The attackers run a Base64-encoded PowerShell command to install both DLLs as Windows services — a split architecture Kaspersky believes was chosen to make detection by EDR tools more difficult. The adversary also establishes SSH reverse tunnels, takes a memory dump of the lsass.exe process, and issues system queries such as hostname and whoami during post‑compromise activity.
Parallel campaign: ViPNet update mechanism hijacked to load HelloInjector and HelloProxy
Weeks earlier, Kaspersky described a separate APT-style operation that abuses the ViPNet product suite update mechanism. In that campaign a malicious DLL named "wtsapi32.dll" — called HelloInjector by researchers — is sideloaded by the legitimate updater "itcsrvup64.exe," causing the payload to execute from within svchost.exe. The loader seeks a process whose name contains "svchost" and whose command line includes "netsvcs," then injects itself using NtWriteVirtualMemory and NtCreateThreadEx. When the conditions are met, HelloInjector drops a plaintext payload named HelloProxy, a hidden proxy and loader for additional modules. Those modules include HelloExecutor, which can execute commands and launch SSH tunnels, and HelloCleaner, which erases ViPNet logs and other forensic artifacts. Kaspersky also found a Rust implant named HelloBackdoor capable of file uploads and downloads, with arbitrary or nonconforming commands passed to cmd.exe.
What this means for Russian companies, TrueConf customers, and security teams
- Russian companies in instrumentation, electronics, transport, energy, IT, and software development: several organizations across these sectors were identified as targets of the TrueConf campaign; those using affected server builds should treat exposed update and client-distribution channels as immediate compromise vectors.
- TrueConf customers and administrators: the vendor released patched server versions 5.3.9, 5.4.9, and 5.5.5 on June 18, 2026; Kaspersky advises organizations using TrueConf to download the latest versions to protect against the KLCERT-26-057 and KLCERT-26-058 exploit chain and installer tampering.
- Security operations and incident responders: Kaspersky’s findings underscore the need to monitor for anomalous connections to TCP port 4307, unexpected modifications of "...\public\js\locale.php", Base64 PowerShell service installs, SSH reverse tunnels, lsass.exe dumps, and outbound traffic to cloud storage services like Microsoft OneDrive that could be abused as C2.
This activity follows earlier disclosures tying Head Mare to zero-day exploitation in TrueConf: Positive Technologies reported three vulnerabilities abused since September 2025 to deliver PHP web shells, and Check Point reported exploitation of CVE-2026-3502 in a separate campaign to deploy Havoc C2 in Southeast Asia. Together with the ViPNet update-hijack findings, Kaspersky’s July 2026 detections sketch a pattern in which update and distribution mechanisms for widely used Russian software are leveraged to deliver persistent implants and obscure attacker activity.
The vendor patches dated June 18, 2026, are a concrete mitigation; the open question left by the record is how many TrueConf servers remain unpatched and able to serve poisoned client installers to downstream systems. Organizations that manage TrueConf or ViPNet deployments should verify their versions and their update chains now.




