APT Group “Head Mare” Exploits Unpatched TrueConf Video‑Conferencing Servers to Deploy PhantomCore Malware
What Happened – In July 2026 Kaspersky uncovered an APT‑level campaign by the group Head Mare that chained two newly‑identified vulnerabilities (internal IDs KLCERT‑26‑057 and KLCERT‑26‑058) in TrueConf video‑conferencing servers (versions 5.3.x‑5.5.5). The flaws allowed remote code execution as NT AUTHORITY\SYSTEM, enabling the attackers to replace client installers with a back‑doored version (PhantomCore) and to install a web shell for ongoing control.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the risk of unpatched, high‑privilege vulnerabilities that bypass isolation mechanisms – a direct test of SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management).
- Highlights the need for continuous vulnerability monitoring and documented remediation to provide audit‑ready evidence of due diligence.
- Aligns with Verisq’s Control Mapping capability, which helps organizations map discovered gaps to SOC 2 controls and capture ongoing proof of remediation.
Who Is Affected – Primarily technology and SaaS providers that host or embed TrueConf servers (e.g., enterprise video‑conferencing platforms, managed service providers, and internal IT departments).
Recommended Actions –
- Inventory all TrueConf deployments and verify version numbers.
- Apply the June 18 2026 patches (5.3.9, 5.4.9, 5.5.5) immediately.
- Integrate automated vulnerability scanning for the TrueConf service port 4307/TCP and map findings to SOC 2 CC6.1/CC7.1.
- Capture remediation tickets, patch logs, and configuration snapshots as continuous audit evidence.
Source: SecureList – Head Mare Targets TrueConf Server with PhantomCore
Technical Notes –
- Attack vector: Remote exploitation of two server‑side code‑execution flaws (no CVE IDs disclosed, but vendor‑issued patches).
- Privileges gained: SYSTEM account, enabling full OS control.
- Malware delivered: PhantomCore backdoor, plus a web shell for data collection and further payload distribution.
- Patch status: Fixed in TrueConf Server versions 5.3.9, 5.4.9, 5.5.5 (released June 18 2026).