HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

APT Group Head Mare Exploits Unpatched TrueConf Server Vulnerabilities to Deploy PhantomCore Malware

Kaspersky detected that the Head Mare APT chain‑exploited two unpatched TrueConf video‑conferencing server flaws, achieving SYSTEM‑level code execution and delivering the PhantomCore backdoor. The incident underscores the importance of continuous vulnerability management for SOC 2 audit readiness.

LiveThreat™ Intelligence · 📅 August 11, 2026· 📰 securelist.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securelist.com

APT Group “Head Mare” Exploits Unpatched TrueConf Video‑Conferencing Servers to Deploy PhantomCore Malware

What Happened – In July 2026 Kaspersky uncovered an APT‑level campaign by the group Head Mare that chained two newly‑identified vulnerabilities (internal IDs KLCERT‑26‑057 and KLCERT‑26‑058) in TrueConf video‑conferencing servers (versions 5.3.x‑5.5.5). The flaws allowed remote code execution as NT AUTHORITY\SYSTEM, enabling the attackers to replace client installers with a back‑doored version (PhantomCore) and to install a web shell for ongoing control.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the risk of unpatched, high‑privilege vulnerabilities that bypass isolation mechanisms – a direct test of SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management).
  • Highlights the need for continuous vulnerability monitoring and documented remediation to provide audit‑ready evidence of due diligence.
  • Aligns with Verisq’s Control Mapping capability, which helps organizations map discovered gaps to SOC 2 controls and capture ongoing proof of remediation.

Who Is Affected – Primarily technology and SaaS providers that host or embed TrueConf servers (e.g., enterprise video‑conferencing platforms, managed service providers, and internal IT departments).

Recommended Actions

  • Inventory all TrueConf deployments and verify version numbers.
  • Apply the June 18 2026 patches (5.3.9, 5.4.9, 5.5.5) immediately.
  • Integrate automated vulnerability scanning for the TrueConf service port 4307/TCP and map findings to SOC 2 CC6.1/CC7.1.
  • Capture remediation tickets, patch logs, and configuration snapshots as continuous audit evidence.

Source: SecureList – Head Mare Targets TrueConf Server with PhantomCore

Technical Notes

  • Attack vector: Remote exploitation of two server‑side code‑execution flaws (no CVE IDs disclosed, but vendor‑issued patches).
  • Privileges gained: SYSTEM account, enabling full OS control.
  • Malware delivered: PhantomCore backdoor, plus a web shell for data collection and further payload distribution.
  • Patch status: Fixed in TrueConf Server versions 5.3.9, 5.4.9, 5.5.5 (released June 18 2026).
📰 Original Source
https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →