TrueConf Servers Hijacked to Distribute PhantomCore Malware

Security researchers have uncovered a major breach involving TrueConf servers, where attackers bundled official video conference software installers with PhantomCore malware. The servers, used by Russian organizations, delivered what appeared to be legitimate TrueConf clients, but each came with a hidden malicious payload tied to the Head Mare APT group.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/))

The intrusion exploited two vulnerabilities—dubbed KLCERT-26-057 and KLCERT-26-058—to breach TrueConf servers. The first allowed unauthenticated access via TCP port 4307, enabling the attacker to execute a stored script. The second permitted escalation beyond an isolated environment, giving attackers full SYSTEM privileges.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/))

Compromising the Trust Chain

Once inside, the attackers replaced genuine server files with a malicious web shell. They explored internal infrastructure, accessed databases with elevated permissions, and swapped out official TrueConf client installers with compromised versions.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/)) On Windows machines, the adversaries installed backdoor services named SysExcSvc and SysReadSvc, using Microsoft OneDrive as their command-and-control channel.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/)) Linux systems got hit too—with a backdoor that conceals its files, monitors TrueConf network traffic, and communicates via GitHub.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/))

Participants who joined video calls hosted on compromised servers were prompted to download a new client. That setup quietly installed the real TrueConf application along with PhantomCore masquerading as a DLL, giving attackers remote code execution on users’ systems.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/)) A registry entry ensured persistence across restarts. Even organizations without on-premises TrueConf servers are at risk if staff join calls hosted on compromised external servers.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/))

Patching & Indicators of Compromise

TrueConf patched both vulnerabilities in server versions 5.3.9, 5.4.9, and 5.5.5, with those updates released on June 18, 2026. Security analysts found that all server builds published since 2022 were vulnerable ahead of that patch.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/)) Administrators have been urged to upgrade immediately and to scan for signs of compromise—file hashes, domain names, suspicious service names like SysExcSvc or SysReadSvc, or malicious DLLs.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/))

Recommended remediation steps include full antivirus scans with current signature sets, resetting passwords for potentially affected accounts, and reaching out to security incident response teams for deeper analysis where indicators are detected.([cybersecuritynews.com](https://cybersecuritynews.com/hackers-exploit-trueconf-servers/))

This case sharply illustrates how software supply chains and trusted vendors can be weaponized. When trust in a communication tool is broken, it becomes an attack vector—not just a risk to infrastructure, but to any end user who thinks they’re downloading safe, legitimate software. It sets a benchmark warning for other vendors: even sound protocols need continuous scrutiny, and fixes need rapid deployment. Monitoring upcoming reports and threat intelligence updates will be crucial to staying ahead.