CVE Tools
Back to blog

Head Mare Weaponized TrueConf's Own Video-Call Client to Backdoor Its Users — CISA Added Both Bugs to KEV a Week After Disclosure

Two unauthenticated flaws let an APT group turn a video conferencing server into a malware-signing machine — trojanizing the official client installer that gets pushed to everyone who joins a call. EPSS still rates both bugs under 1%.

Head Mare Weaponized TrueConf's Own Video-Call Client to Backdoor Its Users — CISA Added Both Bugs to KEV a Week After Disclosure. Two unauthenticated flaws let an APT group turn a video conferencin
Head Mare Weaponized TrueConf's Own Video-Call Client to Backdoor Its Users — CISA Added Both Bugs to KEV a Week After Disclosure. Two unauthenticated flaws let an APT group turn a video conferencin

On August 19-20, 2026, CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog. TrueConf is a video-conferencing platform widely deployed across Russian industry and government. Kaspersky's ICS CERT had disclosed the flaws twelve days earlier, alongside a report that a group it now classifies as an APT — Head Mare — had already been chaining them since July to do something more interesting than a typical breach: replace the legitimate TrueConf client installer with a backdoored one, so that everyone who joined a call through a compromised server downloaded malware along with the app.

Neither bug has a public exploit. Neither scores above 1% on EPSS. Both were patched in June, seven weeks before this story broke. None of that stopped a nation-state-adjacent actor from using them as a foothold to poison a communications tool at the source.

9.8 / 9.0CVSS (72529 / 72530)NVD-scored, CVSS 3.1
0.28% / 0.34%EPSS (72529 / 72530)21st / 27th percentile — below average
0Public exploits indexedNo Metasploit, Nuclei, or GitHub PoC found
~7 weeksPatch → confirmed exploitationFixed June 18, exploited by July 2026

Two bugs, one unauthenticated path to root

Both flaws sit on TrueConf Server's port 4307/TCP, which is open by default. Kaspersky's advisories (KLCERT-26-057 and KLCERT-26-058, mapped to CVE-2026-72529 and CVE-2026-72530) describe a two-stage chain, credited to Kaspersky Principal Security Researcher Vyacheslav Kopeytsev:

  1. CVE-2026-72529 (CWE-306, Missing Authentication for Critical Function) — an unauthenticated attacker calls an undocumented function over port 4307 to run an arbitrary script. NVD scores it CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
  2. CVE-2026-72530 (CWE-94, Code Injection) — that script initially runs inside an isolated sandbox. A second, specially crafted script breaks out of the sandbox and executes arbitrary code on the host OS with NT AUTHORITY\SYSTEM. NVD scores it CVSS 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) — the AC:H reflects that Kaspersky's own advisory notes the escape 'may take several attempts.'

From sandbox escape to trojanized installer

Head Mare's TrueConf attack chain

  1. Unauthenticated connection to port 4307/TCP
  2. CVE-2026-72529: call undocumented function, run script
  3. Script executes inside isolated sandbox
  4. CVE-2026-72530: sandbox escape
  5. Code execution as NT AUTHORITY\SYSTEM
  6. Web shell replaces public/js/locale.php
  7. Recon + privileged access to TrueConf database
  8. Official client installer swapped for trojanized build
  9. Call participants download PhantomCore backdoor
  10. PhantomGraph backdoor deployed, C2 over OneDrive

Who Head Mare is, and why this isn't their first TrueConf campaign

Kaspersky had previously tracked Head Mare as a hacktivist crew. It has now reclassified the group as an APT, citing 'the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures.' Current campaigns target Russian organizations across instrument manufacturing, electronics, transportation, energy, IT and software development, using phishing, exploitation of public-facing servers, and subcontractor compromise as entry points.

TrueConf specifically has been a repeat target. Positive Technologies disclosed a separate set of three TrueConf vulnerabilities (tracked under Russia's BDU identifiers, not the CVEs in this piece) in April 2026, reporting that Head Mare had been exploiting them since September 2025 to drop PHP web shells. This latest chain — CVE-2026-72529 and CVE-2026-72530 — is a second, distinct set of bugs in the same product, used for a more ambitious payload: not just a foothold, but a supply-chain-style trojanization of the software TrueConf's own users trust.

TrueConf / Head Mare timeline

  1. Earlier Head Mare campaign begins
    A separate set of TrueConf zero-days (BDU-2025-10114/10115/10116) exploited to deliver PHP web shells, per Positive Technologies.
  2. Positive Technologies discloses the earlier flaws
    Reports the Sept 2025 campaign and the BDU-tracked vulnerabilities publicly.
  3. TrueConf patches CVE-2026-72529 / CVE-2026-72530
    Fixed in versions 5.3.9, 5.4.9 and 5.5.5.
  4. Kaspersky detects renewed Head Mare activity
    The now-patched flaws exploited against unpatched TrueConf servers to deploy PhantomCore and PhantomGraph.
  5. Kaspersky ICS CERT + Securelist publish
    Advisories for both CVEs plus the full Head Mare technical report go live.
  6. CISA adds both CVEs to KEV
    Federal deadline follows under BOD 22-01.
CVE-2026-72529CVE-2026-72530
CWECWE-306 — Missing Authentication for Critical FunctionCWE-94 — Code Injection
Role in chainInitial unauthenticated script executionSandbox escape to host-level code execution
CVSS (NVD)9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
EPSS0.28% (21st pct.)0.34% (27th pct.)
Public exploit codeNone foundNone found
ATT&CKT1190 Exploit Public-Facing ApplicationT1059 Command and Scripting Interpreter

What's independently checkable vs. what rests on Kaspersky's telemetry

Verifiable from public records
  • CVE-2026-72529 and CVE-2026-72530 exist, with the CWE, CVSS vectors and affected-version ranges above (NVD).
  • Both were added to CISA's KEV catalog on Aug 19-20, 2026.
  • TrueConf shipped fixes in 5.3.9 / 5.4.9 / 5.5.5 on June 18, 2026.
  • No public exploit code is indexed anywhere we checked (Metasploit, Nuclei, ExploitDB, GitHub).
Reported by Kaspersky, not independently confirmed here
  • Attribution of the exploitation to 'Head Mare' specifically, and its reclassification from hacktivist to APT.
  • The PhantomCore / PhantomGraph malware analysis, IOCs, and the OneDrive-as-C2 detail.
  • The named target sectors (instrumentation, electronics, transport, energy, IT, software development) — no individual victims are named by Kaspersky either.
  • The tie to the earlier Sept 2025 / April 2026 Positive Technologies campaign as the 'same actor, second attempt.'

What to actually do

  • Patch TrueConf Server to 5.3.9, 5.4.9 or 5.5.5 (or later) — this closes both CVEs.
  • Do not expose port 4307/TCP to the internet; restrict it to trusted management networks if it must exist at all.
  • If you run an unpatched or recently-patched server, run a full AV scan and check for the indicators of compromise in Kaspersky's report (web shell hash, trojanized installer hash, C2 IPs/domains) before trusting it's clean.
  • If your organization received TrueConf client installers from a third-party server (a partner's or vendor's instance) between July and August 2026, verify the installer's signature/hash against TrueConf's official release rather than assuming it's legitimate.
  • Federal agencies: both CVEs are KEV-listed under BOD 22-01 — check your internal remediation deadline.

Vulnerability data current as of 2026-08-21live record →

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store