Back to Feed
Nation-stateApr 27, 2026

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks

PhantomCore hacktivists exploit TrueConf vulnerabilities to breach Russian networks.

Summary

Pro-Ukrainian hacktivist group PhantomCore has been actively targeting TrueConf video conferencing servers in Russia since September 2025, according to Positive Technologies research. The threat actors are leveraging an exploit chain of three vulnerabilities to achieve remote command execution on vulnerable systems. This represents a coordinated campaign against Russian infrastructure using publicly disclosed or newly discovered flaws.

Indicators of Compromise

  • malware — PhantomCore

Entities

PhantomCore (threat_actor)TrueConf (product)Positive Technologies (vendor)