TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
thehackernews.com Aug 10, 2026

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

AI-summarised brief · reviewed before publication

Head Mare exploited unpatched TrueConf videoconferencing servers to replace legitimate client installers with poisoned versions containing the PhantomCore backdoor. The attacks, detected by Kaspersky in July 2026, leveraged vulnerabilities KLCERT‑26‑057 and KLCERT‑26‑058 to achieve arbitrary code execution with elevated privileges on TrueConf server versions 5.3.x–5.5.5. A web shell enabled data collection, privileged database access, and installation of dual‑component malware (SysExcSvc.dll and SysReadSvc.dll) to evade detection. The vendor released patched server releases on June 18 2026, and affected organizations are urged to upgrade.

💡 Why It Matters

  • · The incident demonstrates how attackers can subvert trusted update mechanisms to deploy sophisticated, stealthy malware, underscoring the critical need for timely patching and vigilant monitoring of software supply chains.