Urgent.News

the world's headlines, one feed

Editions

Tech

Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates

Head Mare Breaches TrueConf: From SYSTEM Privileges to Trojanized Legitimate Client Updates 1. Basic Information Article Title : Hackers breach TrueConf to trojanize client installers with backdoors Publisher : BleepingComputer Publication Date : August 8, 2026, 10:16 (As noted in the article) Original Source : BleepingComputer Primary Source : Kaspersky Securelist Related Malware : PhantomCore,…

Abstract editorial illustration

TrueConf, a video conferencing software, was breached by hackers known as Head Mare, who exploited vulnerabilities to gain SYSTEM privileges, replace legitimate client updates with Trojanized installers, and create a web shell. The attackers used two main methods: compromising the TrueConf Server and replacing the client installer with a malicious version.

The vulnerability chain was previously reported as CVE-2026-3502 / Operation True Chaos. Head Mare utilized scripts and exploits, such as KLCERT-26-057 and KLCERT-26-058, to gain access and elevate privileges. Once inside, the attackers replaced the TrueConf Server's locale.php file with a PHP web shell, allowing them to control the server and distribute the Trojanized installers.

They then deployed PhantomCore, a Trojan, onto the endpoint, granting them access to the TrueConf database and enabling further malicious activities. The attackers maintained persistence through various methods, including a Windows service, a CLSID under HKCU, and a web shell. The compromise spread to clients and partners via the legitimate distribution channel, leading to credential theft, reconnaissance, and further command execution.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written; read the original for the full account.

Read the original at dev.to →

More in Tech

★ Retraction: The App Store Rejection of the Week That Was, in Fact, a Correct Rejection

My disdain for astrology is so utter, and my esteem for Godier’s previous work so high, that it simply never occurred to me that he might have actually made and submitted to the App Store an astrology…

  • Article "App Store Rejection of the Week: Dark Hours" retracted due to incorrect premise
  • App "Dark Hours" was astrology-focused, not as initially claimed
  • Terry Godier's app was accurately rejected by App Store

Counting the days, revisited

  • Improved algorithm counts Gregorian dates to Julian Day numbers
  • Adjusts for leap days, aligns January and February correctly
  • Optimized calculations using multiply-and-shift operations

Dithered QR codes

  • QR codes consist of function patterns and data modules
  • Brands modify data modules for distinctive codes
  • Floyd-Steinberg dithering improves noisy QR codes