Back to advisories

Hackers breach TrueConf to trojanize client installers with backdoors

Head Mare group is actively exploiting unpatched TrueConf servers to distribute trojaned client installers containing PhantomCore and PhantomGraph malware. Affected organizations in Russia and potentially beyond risk credential theft, data exfiltration, and persistent backdoor access. This is a supply chain attack vector targeting end users who download compromised installers.

CRITICALAdvisoryAug 10, 2026
Action required
Immediately identify all TrueConf deployments in your environment. Patch all unpatched TrueConf servers to latest version. Quarantine and re-download TrueConf client installers from official sources only. Scan endpoints for PhantomCore and PhantomGraph signatures and monitor for C2 communications.
Affected products
TrueConfKasperskyCheckPoint Research