← Back to Feed
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
August 10, 2026 · The Hacker News · Severity: HIGH
The threat actor Head Mare is weaponizing security flaws in unpatched TrueConf servers to replace client installers with PhantomCore malware. These attacks target Russian companies across multiple sectors, and Kaspersky detected them in July 2026.
Key Takeaways
- Head Mare exploits TrueConf Server flaws to replace client installers with PhantomCore.
- Attacks target Russian companies in instrumentation, electronics, transport, and energy sectors.
- Kaspersky detected the attacks in July 2026, leveraging unpatched TrueConf servers.