[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7KUbjLcxqUSkjyCgFRmbEPfYT6AhnkeJBXPNsB2mI30":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"0499a891-4cfd-4a26-b397-322741a8b36f","unpatched-trueconf-servers-used-to-backdoor-video-conference-participants","0bb07bc8-1da3-4a1f-8c38-e487cb2eef4c","Unpatched TrueConf Servers Used to Backdoor Video Conference Participants","The Head Mare APT group exploited two unpatched vulnerabilities in TrueConf video conferencing servers to gain system-level privileges and replace legitimate client installers with trojanized versions containing the PhantomCore and PhantomGraph backdoors. This is a classic software supply chain attack facilitated by poor patch hygiene — leaving a public-facing server unpatched created the initial foothold. The use of Microsoft OneDrive for command-and-control (C2) communications demonstrates how attackers abuse trusted cloud services to blend malicious traffic with legitimate network activity. This incident matters because every user who downloaded the compromised installer became an unwitting victim, multiplying the blast radius far beyond the initial server compromise.","**Immediate actions:**\n- Apply all available patches or vendor-issued mitigations for TrueConf Server (addressing KLCERT-26-057 and KLCERT-26-058) immediately.\n- Audit all software distribution mechanisms (installers, update servers) to verify cryptographic integrity of binaries being served to end users.\n- Block or monitor outbound connections to personal\u002Ffree OneDrive tenants from corporate endpoints to disrupt C2 channels.\n\n**Long-term improvements:**\n- Implement a formal vulnerability management program with SLA-driven patch windows (e.g., critical vulnerabilities patched within 24–72 hours).\n- Enforce code-signing and hash verification for all software packages distributed via internal or vendor-hosted servers.\n- Apply network segmentation to isolate video conferencing infrastructure from sensitive internal systems and limit lateral movement.\n\n**Detection measures:**\n- Deploy file integrity monitoring (FIM) on all software distribution directories to alert on unauthorized installer modifications.\n- Enable behavioral endpoint detection to flag unusual processes spawned by video conferencing client installers.\n- Monitor for anomalous outbound traffic to cloud storage providers (OneDrive, Dropbox, etc.) that may indicate C2 beaconing.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","CIS Control 13: Network Monitoring and Defense","NIST SP 800-40 Rev 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST SA-12: Supply Chain Protection","NIST SI-7: Software, Firmware, and Information Integrity","NIST SC-7: Boundary Protection (Network Segmentation)","MITRE ATT&CK T1195.002: Supply Chain Compromise – Software Supply Chain","MITRE ATT&CK T1102: Web Service (C2 via OneDrive)","ITIL Change Management: Emergency Change Procedures for Critical Patches","GDPR Article 32: Security of Processing (obligation to patch known vulnerabilities)","published","2026-08-11T15:20:23.117421+00:00","2026-08-11T15:20:22.788+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fsecurelist.com\u002Ftr\u002Fhead-mare-targets-trueconf-server-with-phantomcore\u002F120988\u002F","head-mare-apt-is-exploiting-vulnerabilities-in-an-unpatched-trueconf-server-to-d-5533e3","Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]