CVE Tools
Back to feed
Exploited in the wild TrueConf Server Head Mare malware ViPNet Suite TrueConf

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Kaspersky reports that the threat actor Head Mare has actively exploited unpatched TrueConf Server instances to deploy the PhantomCore backdoor and RAT. By chaining vulnerabilities KLCERT-26-057 and KLCERT-26-058, attackers achieve SYSTEM-level code execution and replace legitimate client installers with malicious versions affecting organizations across various Russian industries. This attack vector allows for persistent remote access via a web shell and the installation of additional backdoors like PhantomGraph.

Additionally, separate findings reveal an APT campaign hijacking ViPNet Suite update mechanisms to distribute HelloInjector and HelloProxy malware, targeting government and critical infrastructure sectors. While the TrueConf issues were addressed in versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026, organizations using ViPNet must investigate potential compromise of their update services.