← Back to Feed

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

August 10, 2026 · The Hacker News · Severity: HIGH

The threat actor Head Mare is weaponizing security flaws in unpatched TrueConf servers to replace client installers with PhantomCore malware. These attacks target Russian companies across multiple sectors, and Kaspersky detected them in July 2026.

Key Takeaways

  • Head Mare exploits TrueConf Server flaws to replace client installers with PhantomCore.
  • Attacks target Russian companies in instrumentation, electronics, transport, and energy sectors.
  • Kaspersky detected the attacks in July 2026, leveraging unpatched TrueConf servers.
☕ Buy a Coffee