Kaspersky has issued a security warning regarding active cyberattacks targeting unpatched TrueConf videoconferencing servers. The cybersecurity firm identified a multi-stage campaign conducted by the Head Mare advanced persistent threat (APT) group. This group uses the vulnerabilities to install PhantomCore and PhantomGraph backdoors on compromised systems.

Exploitation of TrueConf videoconferencing servers

The attackers exploit specific flaws in unpatched TrueConf videoconferencing servers to gain unauthorized access. According to Kaspersky, the vulnerabilities were addressed by the vendor in updates released on June 18, 2026. The security patches are available in TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5. Organizations running older versions remain vulnerable to these exploits.

To execute the compromise, the threat actors exploit two vulnerabilities, tracked under the internal identifiers KLCERT-26-057 and KLCERT-26-058. These flaws allow attackers to execute arbitrary code with maximum privileges on the host system. Once inside, the attackers replace a legitimate server file with a custom web shell to maintain access.

Mechanism of the Multi-Stage Attack

The web shell enables the attackers to gather detailed information about the target organization’s IT infrastructure. They also gain privileged access to the server database. Consequently, the attackers replace the legitimate client installer with an infected version. When users connect to the compromised server, they are prompted to download this modified client application under the guise of an update.

This delivery method ensures that malware is installed directly onto the user’s device. The attack affects TrueConf server versions 5.3.X prior to 5.3.9, 5.4.X prior to 5.4.9, and 5.5.X prior to 5.5.5, as well as older legacy releases.

Risks to External Participants

The threat extends beyond the organizations hosting the vulnerable software. Evgeny Goncharov, Head of Kaspersky ICS CERT, stated that the campaign is dangerous because it affects external counterparties. Employees of companies that do not use TrueConf videoconferencing servers can still be compromised when joining meetings hosted on infected systems. This highlights the interconnected nature of modern telecommunications networks.

“This campaign is particularly dangerous because it puts at risk not only organizations using unpatched TrueConf servers. Even if a company doesn’t use this solution, its employees can connect to compromised servers at the invitation of their counterparties to participate in online meetings.”

Evgeny Goncharov, Head of Kaspersky ICS CERT

Recommended Mitigation Steps

To mitigate these risks, Kaspersky recommends that organizations immediately update their servers to the patched versions. Security teams should scan their networks for indicators of compromise. If any malicious activity is detected, administrators must perform an unscheduled password reset for all potentially compromised accounts.

Furthermore, organizations should run full system scans using updated antivirus databases. Continuous vulnerability monitoring and prompt patch application are essential to defend against such threats. Providing security specialists with threat intelligence data can also help counter these tactics.