# Russia's Sovereign Video Platform Just Became a Backdoor Factory
When Russian enterprises migrated away from Zoom and Microsoft Teams, TrueConf was the pitch: domestically developed, on-premise, trustworthy. The Head Mare hacktivist group apparently found that pitch hilarious.
Kaspersky researchers disclosed this week that Head Mare has been systematically compromising TrueConf servers and replacing legitimate client installers with backdoored versions — turning the very update mechanism employees trust into a malware delivery pipeline. The attack, discovered in July, is technically clever, strategically targeted, and a case study in why "sovereign infrastructure" doesn't automatically mean "secure infrastructure."
## How They Got In
The entry point was embarrassingly simple: TCP port 4307, open by default on TrueConf Server installations, accepting unauthenticated connections. Head Mare used two vulnerabilities — KLCERT-26-057 and KLCERT-26-058 — to chain code execution inside TrueConf's isolated environment and then escape the sandbox entirely.
From there, the path to full system control was methodical. The attackers escalated privileges to NT AUTHORITY\SYSTEM, swapped out a legitimate PHP file (\public\js\locale.php) with a web shell, and planted themselves a persistent remote access channel into the compromised server. All of this before touching a single endpoint in the organization.
The web shell gave them access to the TrueConf database and, more critically, control over what clients download when they connect. Head Mare replaced the legitimate TrueConf installer with a malicious version carrying the PhantomCore backdoor. No popped endpoint, no phishing click — just a poisoned update waiting for the next person who opened the conferencing app.
## The Update You Didn't Know Was Malware
The insidious detail here is that employees had no reason to be suspicious. They connected to their organization's own internal TrueConf server — the one IT manages, the one that's supposed to be safe — and received an installer that looked exactly like a normal client update. It wasn't digitally signed, but most users don't check that.
Kaspersky includes a warning that deserves emphasis: organizations that *don't* run TrueConf servers are still exposed. If employees connect to a *counterparty's* TrueConf server for an external meeting, they could pull down an infected installer from that compromised environment. The blast radius extends beyond direct victims to anyone in their meeting ecosystem.
That's supply chain risk through a vector most defenders aren't modeling — not a compromised npm package or a poisoned build pipeline, but a trusted meeting platform used in routine B2B communication.
## PhantomGraph and the Microsoft Irony
Alongside PhantomCore, Head Mare deployed PhantomGraph, a two-DLL backdoor with an unusual command-and-control mechanism: a Microsoft OneDrive account. The malware receives commands from the OneDrive folder, executes them, and returns results — using Microsoft's own cloud infrastructure as a covert channel against Russian organizations that adopted TrueConf specifically to reduce Microsoft dependency.
The observed activity through PhantomGraph included LSASS memory dumps for credential harvesting, basic reconnaissance (hostname, whoami), and establishing reverse SSH tunnels for persistent access. This is the toolkit of a group that wants to stay inside the network — not just make noise.
Head Mare, classified broadly as hacktivists, has been running concurrent campaigns against Russian organizations in instrumentation, electronics, transportation, energy, IT, and software development. The sector diversity suggests either broad opportunism or a deliberate effort to map and compromise industrial and critical infrastructure.
## TrueConf's Rough Year
This is not the first time TrueConf has featured in a serious attack disclosure in 2026. In April, Check Point Research documented Operation True Chaos, attributing attacks exploiting a zero-day arbitrary file execution flaw (CVE-2026-3502) to Chinese threat actors using the Havoc implant. That campaign also leveraged trojanized client updates as a delivery mechanism.
Two separate threat actor groups — one attributed to Russian hacktivism, one tentatively linked to China — independently identified TrueConf's update distribution as a high-value attack surface within months of each other. That's not a coincidence. It's a signal that this vector was recognized as lucrative and underdefended, and that TrueConf's security posture has been broadly assessed as lacking.
TrueConf released patches for the vulnerabilities Kaspersky disclosed — versions 5.3.9, 5.4.9, and 5.5.5 were published June 18. Organizations running older versions of 5.3.x, 5.4.x, 5.5.x, or anything older than that should assume they're exposed.
## Patching Is Necessary but Not Sufficient
For defenders, the immediate action is straightforward: update TrueConf Server immediately if you haven't already. But that's the floor, not the ceiling.
Kaspersky's warning about counterparty exposure means that even organizations running fully patched, internally secure TrueConf deployments should think about who their employees connect to externally. Meeting invitations from vendors, partners, and contractors could be pulling software from compromised servers.
Beyond TrueConf specifically, this attack illustrates a broader pattern that deserves attention: on-premise video conferencing infrastructure is almost never treated with the same scrutiny as email gateways or VPN concentrators, despite being an authenticated entry point that touches every employee's workstation. Port 4307 shouldn't be open without authentication. The TrueConf database shouldn't be accessible from a compromised web server. The update distribution path shouldn't be rewritable by anyone who can reach the server.
These aren't novel misconfigurations — they're basic security hygiene that the sovereignty pitch obscured.
---
## HackWire Analysis
The TrueConf compromise deserves attention beyond its immediate impact because it exposes a structural vulnerability in how sovereign tech alternatives get evaluated.
When Russian enterprises adopted TrueConf as a Zoom/Teams replacement after 2022, the evaluation criteria were geopolitical: domestic, auditable, on-premise, not subject to Western sanctions or data sharing requirements. What that evaluation didn't adequately weight was the security engineering maturity of the vendor itself. The result is a platform that achieved critical enterprise and government adoption while harboring unauthenticated network services and sandbox escape chains that two separate threat actor groups found independently in the same year.
This pattern repeats across sovereign infrastructure plays globally. The political imperative to adopt domestic alternatives creates pressure to ship and scale before the security fundamentals are solid. Buyers accept risk they wouldn't tolerate from an incumbent vendor because the alternative is dependence on foreign technology. It's a reasonable tradeoff in some contexts — but it's still a tradeoff, and security teams need to account for it explicitly rather than assuming "on-premise" and "domestic" are synonymous with "trustworthy."
The PhantomGraph OneDrive C2 channel is worth flagging separately. Blocking Microsoft cloud services wholesale isn't an option for most organizations — OneDrive, SharePoint, and Teams are business-critical. Attackers have noticed, and the use of legitimate cloud storage for C2 is increasingly common precisely because it blends into normal traffic. Behavioral detection — large or unusual volumes of sync activity, syncing from non-standard system paths, OneDrive processes spawning unexpected children — is more effective here than domain or IP blocklisting.
Security teams watching Head Mare campaigns should also note the LSASS dumping. That's an indicator of credential theft intent, not just persistence. If you find PhantomGraph on a host, assume the credentials on that machine and in its memory are compromised, and rotate accordingly.
— *HackWire Editorial*
---
## Related Coverage