[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors-msn6qzzd":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"f8460688-0270-443a-9f7c-ed1741c66a22","Hackers breach TrueConf to trojanize client installers with backdoors","hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors-msn6qzzd","Head Mare group is actively exploiting unpatched TrueConf servers to distribute trojaned client installers containing PhantomCore and PhantomGraph malware. Affected organizations in Russia and potentially beyond risk credential theft, data exfiltration, and persistent backdoor access. This is a supply chain attack vector targeting end users who download compromised installers.","critical","advisory",[],[13,14,15],"TrueConf","Kaspersky","CheckPoint Research","Immediately identify all TrueConf deployments in your environment. Patch all unpatched TrueConf servers to latest version. Quarantine and re-download TrueConf client installers from official sources only. Scan endpoints for PhantomCore and PhantomGraph signatures and monitor for C2 communications.",[18],"31526b03-bb0f-42f6-98a5-0f0eb8635cee",null,[21],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-breach-trueconf-to-trojanize-client-installers-with-backdoors\u002F","archived","2026-08-12T12:06:11.785+00:00","2026-08-10T12:06:15.03771+00:00","2026-08-12T13:05:48.43809+00:00",[27],{"id":18,"title":6,"url":21}]