TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Summary

The threat actor Head Mare is actively exploiting unpatched TrueConf server vulnerabilities to target Russian companies across various sectors. These attacks involve a chain of vulnerabilities that allow for the replacement of client installers with malicious software known as PhantomCore.

IFF Assessment

FOE

The exploitation of vulnerabilities in widely used software like TrueConf to deliver malicious payloads represents a direct threat to organizations and their data.

Defender Context

This incident highlights the ongoing risk posed by unpatched server software and the need for robust vulnerability management and threat hunting. Defenders should be aware of active exploitation campaigns targeting specific software and ensure timely patching of critical systems.

Read Full Story →