started · updated
TrueConf software targeted in supply chain attack by Head Mare
The hacker group Head Mare has conducted a supply chain attack against the video conferencing software provider TrueConf. By exploiting two vulnerabilities in unpatched TrueConf servers (identified as KLCERT-26-057 and KLCERT-26-058), attackers gained system rights and replaced legitimate client installation packages with versions containing backdoors.
The compromised installers include two types of malware: PhantomCore and PhantomGraph. PhantomCore allows for remote control and data extraction, while PhantomGraph utilizes Microsoft OneDrive accounts to receive commands and exfiltrate data, such as memory dumps of the LSASS process to steal credentials.
Reports indicate the attack primarily targets Russian organizations using the software. Affected server versions include 5.3.x (prior to 5.3.9), 5.4.x (prior to 5.4.9), and 5.5.x (prior to 5.5.5). While TrueConf released patches on June 18, the campaign remained undetected for a significant period.
Entities
Head Mare · Kaspersky · PhantomCore · PhantomGraph · TrueConf