Head Mare Turns TrueConf Updates Into Malware Delivery

Head Mare has been exploiting TrueConf Server flaws to replace client installers with PhantomCore in attacks Kaspersky detected in July 2026. The affected servers include TrueConf Server 5.3.x through 5.5.5, plus earlier versions, and the activity has hit Russian organizations in manufacturing, transportation, energy, IT, and software development. The mechanism is simple and ugly: TrueConf servers are trusted to hand out client installers, so once attackers get control of the server they can swap the normal package for a poisoned one. Users then download what looks like an ordinary update, but the installer delivers malware instead. If your environment uses a self-hosted server or portal to distribute client software, the update channel itself becomes part of the attack surface. A compromised server can keep serving tainted installers even after the initial intrusion is noticed, so the exposure sits in the distribution path, not just on the endpoint.

Part of the PlainSec briefing for 2026-08-10

Every edition of this story: Head Mare Turns TrueConf Updates Into Malware Delivery

Sources