Hackers Hijack TrueConf Servers to Deliver Backdoored Video Conferencing Software

The hacktivist group Head Mare targets unpatched TrueConf video conferencing servers, exploiting critical vulnerabilities to execute code with the highest privilege levels. TrueConf, a secure on-premise alternative to Zoom and Microsoft Teams, is widely used across Russian enterprise and government sectors. Kaspersky researchers discover that attackers leverage default open ports to access servers without authentication, then escalate privileges to install persistent web shells for ongoing remote access.

Once inside, attackers replace legitimate TrueConf client installers hosted on compromised servers with malicious versions containing the PhantomCore backdoor. When users connect to their local server for updates, they unknowingly download the trojanized installer. Kaspersky warns that even organizations not running TrueConf face risk, as employees joining meetings on infected third-party servers receive the poisoned software package. The attackers also deploy PhantomGraph, a separate backdoor that communicates through Microsoft OneDrive to exfiltrate credentials and conduct reconnaissance.

The sophisticated supply chain attack demonstrates how compromised communication platforms serve as powerful distribution channels for malware. PhantomGraph operators dump LSASS process memory to steal credentials and execute reconnaissance commands to map victim networks. Organizations running TrueConf servers should apply available patches immediately, verify the digital signatures of client installers before deployment, and monitor for unusual activity on TCP port 4307.

Read More at the original source →