Back to advisories

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Head Mare APT is actively exploiting two vulnerabilities in unpatched TrueConf servers to deploy PhantomCore and PhantomGraph backdoors to conference participants. Affected organizations using TrueConf are at immediate risk of system compromise and privilege escalation. Attackers are replacing legitimate client installers and using OneDrive for command and control.

CRITICALAdvisoryAug 12, 2026
Action required
Identify and patch all TrueConf servers immediately. Scan for suspicious OneDrive C2 communications and monitor for PhantomCore/PhantomGraph indicators. Check client installer integrity and review conference participant endpoints for signs of compromise.
Affected products
TrueConf ServerMicrosoft