# Head Mare's Supply-Side Gambit: When Your TrueConf Server Becomes the Attacker


Russia's homegrown collaboration stack has a poisoned well problem.


Kaspersky researchers confirmed in July 2026 that Head Mare — a threat actor that has spent the past few years methodically picking apart Russian enterprise infrastructure — has returned to TrueConf servers with a refined playbook. The group is chaining vulnerabilities in unpatched TrueConf deployments to do something cleverer than simply exfiltrating data: they're replacing client installers with PhantomCore-laced packages, turning every employee download into an infection vector.


The sectors hit read like a strategic targeting sheet — instrumentation, electronics, transport, energy, IT, and software development. These aren't opportunistic smash-and-grab targets. This is someone who wants long-term, persistent visibility into Russian industrial operations.


## The Installer Swap: A Supply Chain Attack Without the Supply Chain


Let's be precise about what's happening here, because it matters for how defenders frame the threat.


This is not a traditional software supply chain compromise. Kaspersky's finding describes server-side exploitation — Head Mare breaks into TrueConf Server instances and modifies the hosted installer packages. When an internal user navigates to their company's collaboration server to download or update the TrueConf client, they get PhantomCore instead. No upstream vendor compromise required. No malicious package slipped into a repository.


It's considerably more surgical. The attacker doesn't need to breach TrueConf the company — they just need to breach *your* TrueConf server. And because the download comes from a trusted internal hostname over a presumably trusted connection, endpoint detection has to work harder to flag it.


The psychological element is worth pausing on: the user who downloads from truconf.companyname.ru has no reason to be suspicious. They're updating software the IT department told them to run. The trusted internal source is the attack surface.


## Head Mare's Persistence Problem — and How They Solved It


Head Mare has been documented targeting Russian organizations since at least 2023, and they've shown a consistent preference for exploiting legitimate remote-access and collaboration software. Prior campaigns leveraged WinRAR vulnerabilities and phishing lures themed around Russian government correspondence. The TrueConf focus is a deliberate evolution.


Here's why TrueConf specifically: after 2022, a substantial portion of Russian enterprises migrated away from Western collaboration tools — Zoom, Teams, WebEx — under a combination of regulatory pressure and practical necessity as Western vendors restricted access. TrueConf, a Russian domestic product, filled that gap aggressively. That migration created a large, relatively homogeneous install base running software that many security teams hadn't prioritized for patching precisely because it felt like a "safe" domestic alternative.


Head Mare noticed. A concentrated, under-scrutinized install base with known vulnerability chains is exactly the kind of opportunity a patient threat actor waits for.


PhantomCore itself — a remote access trojan that Kaspersky has been tracking in Head Mare's arsenal — provides the persistent foothold. Once installed via the poisoned client package, it phones home and gives the operator command-and-control over the endpoint. In energy and instrumentation environments, that kind of persistence has implications well beyond data theft.


## What the Vulnerability Chain Actually Tells Us


Kaspersky's report references a "vulnerability chain" without fully unpacking which CVEs are in play — a frustrating omission, though likely deliberate to allow patching time. What the language does tell us is that this isn't a single unpatched bug. Head Mare is combining multiple weaknesses to achieve installer replacement: likely an initial authentication bypass or path traversal to gain server access, followed by write access to the hosted package directory.


Chaining vulnerabilities to replace software installers requires meaningful reconnaissance. The attacker needs to understand TrueConf Server's directory structure, how it serves client packages, and whether integrity verification is in place (apparently it wasn't, or was bypassable). This is not the work of a script kiddie running automated exploits. Someone spent time on TrueConf's architecture.


The unpatched qualifier is doing heavy lifting in Kaspersky's framing. Organizations running current TrueConf versions may be protected — but "current" in a Russian enterprise context often means "whatever version IT deployed 18 months ago when the migration happened." Update cadences for homegrown collaboration software rarely match the urgency applied to, say, Exchange or VPN appliances.


## What Defenders Need to Do Right Now


If you're running TrueConf Server in any environment — Russian enterprise, anyone with subsidiaries there, or organizations using it for compliance reasons — the checklist is short but urgent:


  • Patch immediately. Contact TrueConf for the relevant CVE list and security advisory. If they haven't issued one, treat the absence as a red flag and isolate the server.
  • Audit your hosted installer packages. Hash the packages currently served by your TrueConf installation against known-good hashes from the vendor. If you can't get a clean hash from TrueConf directly, that's a conversation to have with them now.
  • Enable installer signing verification on endpoints. If your TrueConf deployment doesn't cryptographically sign client packages and verify them on install, it's operating without a critical safety net.
  • Review TrueConf Server logs for unexpected write activity. Specifically look for any modification timestamps on installer files that don't correspond to known patching windows.
  • Treat endpoints that downloaded TrueConf clients from internal servers in the past 90 days as potentially compromised. Run PhantomCore IOCs against those endpoints. Kaspersky's threat intelligence feed has the relevant signatures.

  • ---


    ## HackWire Analysis


    The Head Mare–TrueConf story is a case study in how threat actors exploit forced infrastructure migrations.


    The post-2022 scramble to replace Western software with domestic Russian alternatives created a security blind spot that was entirely predictable and almost entirely ignored. Organizations made platform decisions under political and regulatory pressure without conducting the kind of security due diligence they'd apply to a Western vendor. The result: a homogeneous, under-scrutinized attack surface that a patient adversary could study and exploit at leisure.


    This pattern isn't unique to Russia. Every time a large organization makes a rapid platform shift — whether driven by geopolitics, sanctions, regulatory mandates, or cost-cutting — there's a window of elevated risk where the new platform is trusted without being verified. Head Mare is demonstrating exactly how to exploit that window.


    The installer replacement technique is also worth flagging for its potential to proliferate beyond this specific campaign. Once an attacker demonstrates that poisoning server-hosted installers is a viable lateral movement and persistence strategy, expect others to copy it. The technique requires fewer resources than a true supply chain attack and is harder for end users to detect. The defender response — cryptographic package signing with verified keys — is well understood, but adoption remains inconsistent even in environments that should know better.


    For energy and instrumentation operators specifically: the sectors targeted in this campaign are exactly the ones where endpoint persistence can pivot toward operational technology networks. The distance from a PhantomCore RAT on a workstation to a compromised historian or SCADA interface is shorter than most OT security postures assume. If your OT/IT segmentation relies on the assumption that endpoint malware stays on the IT side, this is a good week to stress-test that assumption.


    Head Mare has shown patience and technical sophistication across multiple campaigns. They will not stop at a single tool or exploit chain. Treat this as a signal, not an isolated incident.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)