Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates
Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates 1. Basic Information Article Title : Hackers breach TrueConf to trojanize client installers with backdoors Publisher : BleepingComputer Publication Date : August 8, 2026, 10:16 (As noted in the article) Original Source : BleepingComputer Primary Source : Kaspersky Securelist Related Malware : PhantomCore,…
TrueConf, a video conferencing software, was breached by hackers known as Head Mare, who exploited vulnerabilities to gain SYSTEM privileges, replace legitimate client updates with Trojanized installers, and create a web shell. The attackers used two main methods: compromising the TrueConf Server and replacing the client installer with a malicious version.
The vulnerability chain was previously reported as CVE-2026-3502 / Operation True Chaos. Head Mare utilized scripts and exploits, such as KLCERT-26-057 and KLCERT-26-058, to gain access and elevate privileges. Once inside, the attackers replaced the TrueConf Server's locale.php file with a PHP web shell, allowing them to control the server and distribute the Trojanized installers.
They then deployed PhantomCore, a Trojan, onto the endpoint, granting them access to the TrueConf database and enabling further malicious activities. The attackers maintained persistence through various methods, including a Windows service, a CLSID under HKCU, and a web shell. The compromise spread to clients and partners via the legitimate distribution channel, leading to credential theft, reconnaissance, and further command execution.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written; read the original for the full account.

