CVE-2026-3502
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (92nd percentile).
CISA federal remediation date Apr 16 · date passed
Vulnerabilities & Exploits · Supply Chain
Head Mare has been exploiting TrueConf Server flaws to replace client installers with PhantomCore in attacks Kaspersky detected in July 2026. The affected servers include TrueConf Server 5.3.x through 5.5.5, plus earlier versions, and the activity has hit Russian organizations in manufacturing, transportation, energy, IT, and software development.
The mechanism is simple and ugly: TrueConf servers are trusted to hand out client installers, so once attackers get control of the server they can swap the normal package for a poisoned one. Users then download what looks like an ordinary update, but the installer delivers malware instead.
If your environment uses a self-hosted server or portal to distribute client software, the update channel itself becomes part of the attack surface. A compromised server can keep serving tainted installers even after the initial intrusion is noticed, so the exposure sits in the distribution path, not just on the endpoint.
3 sources · Aug 11
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (92nd percentile).
CISA federal remediation date Apr 16 · date passed
Kaspersky Securelist
Head Mare delivers PhantomCore and PhantomGraph backdoors via an unpatched TrueConf server
The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
originalThe Hacker News
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Head Mare exploits two TrueConf flaws to gain SYSTEM privileges and replace client installers with PhantomCore malware across Russian companies.
originalBleepingComputer
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
originalPart of the PlainSec briefing for 2026-08-10
Every edition of this story: Head Mare Turns TrueConf Updates Into Malware Delivery