CVE Tools

Hackers breach TrueConf to trojanize client installers with backdoors

BleepingComputerBy Bill Toulas

Reported exploitedTrueConfHead Mare

Our summary

The Head Mare hacktivist group has exploited unpatched vulnerabilities in TrueConf video conferencing servers to replace client installers with malicious versions containing backdoors. These exploits allow attackers to execute arbitrary code and deploy PhantomCore and PhantomGraph backdoors. Kaspersky researchers discovered the attacks in July, revealing that the threat actors used default open ports and internal flaws to gain privileged access and maintain persistence on compromised systems. TrueConf users who connect to affected servers could unknowingly download infected installers. The company issued patches for vulnerable versions on June 18.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store