← TrueConf

2026 TrueConf — Head Mare exploits servers to trojanize client installers (Kaspersky)

2026 Unknown records affected Share on X

Data compromised

Sensitive information collection from victim environments and TrueConf database access per Kaspersky; primary impact is supply-chain style delivery of trojanized unsigned client installers to organizations connecting to compromised servers. No public PII headcount — recordsAffected 0.

Technical writeup

Researcher-reported server compromise / installer trojanization — BleepingComputer (August 8, 2026) covering Kaspersky: Head Mare exploited TrueConf video-conferencing servers (default port 4307, sandbox escape to SYSTEM), deployed webshells, accessed databases, and replaced legitimate client installers with malicious PhantomCore-bearing builds so users receive trojanized updates when connecting — including from counterparties’ servers. Catalogued as a confirmed attack technique against TrueConf estates with unknown victim census; not a classic consumer PII dump. Operators should patch, verify installer signatures, and assume lateral movement if 4307 was exposed.

Root cause

Head Mare hacktivists exploited unpatched TrueConf server flaws (Kaspersky KLCERT-26-057/058) via default TCP 4307 to gain SYSTEM, plant webshells, access the TrueConf DB, and replace client installers with PhantomCore/PhantomGraph backdoored builds. Discovered by Kaspersky in July; reported August 8, 2026.

References