Hackers breach TrueConf to trojanize client installers with backdoors
CVE Tools coverage
The Head Mare hacktivist group has exploited unpatched vulnerabilities in TrueConf video conferencing servers to replace client installers with malicious versions containing backdoors. These exploits allow attackers to execute arbitrary code and deploy PhantomCore and PhantomGraph backdoors. Kaspersky researchers discovered the attacks in July, revealing that the threat actors used default open ports and internal flaws to gain privileged access and maintain persistence on compromised systems. TrueConf users who connect to affected servers could unknowingly download infected installers. The company issued patches for vulnerable versions on June 18.