Nation-stateApr 27, 2026
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
PhantomCore hacktivists exploit TrueConf vulnerabilities to breach Russian networks.
Summary
Pro-Ukrainian hacktivist group PhantomCore has been actively targeting TrueConf video conferencing servers in Russia since September 2025, according to Positive Technologies research. The threat actors are leveraging an exploit chain of three vulnerabilities to achieve remote command execution on vulnerable systems. This represents a coordinated campaign against Russian infrastructure using publicly disclosed or newly discovered flaws.
Indicators of Compromise
- malware — PhantomCore
Entities
PhantomCore (threat_actor)TrueConf (product)Positive Technologies (vendor)