Hackers breach TrueConf servers to deliver malicious video conferencing updates
Hacktivist group Head Mare has exploited vulnerabilities in TrueConf's video conferencing server software to inject backdoors into client installers. The attack, which allows for persistent remote access and credential exfiltration, affects multiple versions of the enterprise-focused software.
Key Takeaways
- Head Mare leveraged TCP port 4307 and two specific vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to execute code and escape sandboxes on TrueConf servers.
- The attack replaces 'locale.php' with a web shell, allowing hackers to manipulate the TrueConf database and host malicious client installers.
- Compromised systems deploy the PhantomGraph backdoor, which uses Microsoft OneDrive for command-and-control and dumps LSASS process memory to steal credentials.
- Vulnerabilities affect TrueConf Server versions 5.3.x through 5.5.x; security patches were released by the vendor on June 18, 2026.
Why It Matters
The TrueConf breach demonstrates the high risk of self-hosted streaming infrastructure becoming a vector for supply chain attacks. By compromising the central server, attackers bypass endpoint defenses through a trusted update mechanism, turning a privacy-focused tool into a distributed malware platform. For the streaming industry, this highlights the fragility of the 'on-premise for security' argument if management ports and update integrity checks are not strictly hardened. The immediate threat extends to counterparties who connect to compromised external servers, creating a contagion effect. Stakeholders should monitor for non-digitally signed binaries in update logs as a primary indicator of compromise.
Additional Context
The Head Mare campaign follows a pattern of escalating pressure on Russian enterprise infrastructure. In early 2026, cybersecurity researchers at Kaspersky tracked PhantomCore activity using compromised email addresses to target Aerospace and IT sectors. This coincides with a broader surge in supply chain aggression; per Wiz Research in August 2026, notable supply chain incidents doubled in the first half of the year, accounting for 25% of all significant cyber events. The trend is exacerbated by a collapse in the exploitation window, with Black Kite reporting in July 2026 that attackers are now exploiting flaws a median of seven days before a patch is even available.
This is not the first time TrueConf has been weaponized by state-linked actors. Per Check Point, a campaign dubbed 'Operation True Chaos' targeted the platform in April 2026, leveraging the CVE-2026-3502 zero-day to distribute the Havoc implant. That operation, attributed to Chinese threat actors, similarly focused on government entities in Southeast Asia that utilized the software for air-gapped communications. The repeated targeting of TrueConf by diverse groups—from hacktivists like Head Mare to suspected nation-states—underscores its strategic value as a bridgehead into high-security networks that typically avoid Western cloud-based tools like Zoom or Microsoft Teams. Similar streaming backends vulnerable to policy flaws continue to be a major concern for enterprise security teams. The risk of legitimate update channels being hijacked remains a critical threat vector for all enterprise software.
Read full article at bleepingcomputer.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source