Head Mare Exploits TrueConf Flaws to Trojanize Client Installers with PhantomCore & PhantomGraph

    Date: 08/10/2026

    Severity: High

    Summary

    The Head Mare hacktivist group exploited two TrueConf Server vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to gain SYSTEM-level access and deploy a web shell.

    Attackers then replaced legitimate TrueConf Client installers with trojanized versions containing the PhantomCore and PhantomGraph backdoors, turning the compromise into a supply-chain attack.

    PhantomCore enabled reconnaissance, credential theft including LSASS dumping, and C2, while PhantomGraph used Microsoft OneDrive for C2 and both backdoors established persistence as Windows services. The campaign primarily targeted Russian organizations and highlights the risk of trusted software distribution channels being abused to deliver malware. 

    Indicators of Compromise (IOC) List

    Domain/URLs

    bright-deals.site

    cosmetic-deals.store

    flexish.shop

    media-hub.today

    nova-stream.site

    penzadogshelter.site

    rinomobile.ink

    trendy-market.site

    urbanpixel.store

    vks.gossopka.forum

    IP Address

    194.87.239.71

    194.87.93.153

    31.59.102.61

    38.244.205.244

    81.177.32.12

    Hashes

    489f43be558b2679284ceabed7adc4f3

    4d27b4eb1c5dbb3d8160f29b8119523e

    748c9f8cb1065000616204935f96207f

    c5a460e4e68a088f6e51b2c6474642ec

    dd1fd2b459b97b7d59375cb8383cd19a

    Regsitry

    HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "nova-stream.site" or url like "nova-stream.site" or siteurl like "nova-stream.site" or domainname like "urbanpixel.store" or url like "urbanpixel.store" or siteurl like "urbanpixel.store" or domainname like "flexish.shop" or url like "flexish.shop" or siteurl like "flexish.shop" or domainname like "rinomobile.ink" or url like "rinomobile.ink" or siteurl like "rinomobile.ink" or domainname like "trendy-market.site" or url like "trendy-market.site" or siteurl like "trendy-market.site" or domainname like "penzadogshelter.site" or url like "penzadogshelter.site" or siteurl like "penzadogshelter.site" or domainname like "bright-deals.site" or url like "bright-deals.site" or siteurl like "bright-deals.site" or domainname like "media-hub.today" or url like "media-hub.today" or siteurl like "media-hub.today" or domainname like "vks.gossopka.forum" or url like "vks.gossopka.forum" or siteurl like "vks.gossopka.forum" or domainname like "cosmetic-deals.store" or url like "cosmetic-deals.store" or siteurl like "cosmetic-deals.store"

    Detection Query 2 :

    dstipaddress IN ("81.177.32.12","194.87.93.153","31.59.102.61","38.244.205.244","194.87.239.71") or srcipaddress IN ("81.177.32.12","194.87.93.153","31.59.102.61","38.244.205.244","194.87.239.71")

    Detection Query 3 :

    md5hash IN ("748c9f8cb1065000616204935f96207f","489f43be558b2679284ceabed7adc4f3","4d27b4eb1c5dbb3d8160f29b8119523e","dd1fd2b459b97b7d59375cb8383cd19a","c5a460e4e68a088f6e51b2c6474642ec")

    Detection Query 4 :

    resoursename = "Windows Security" and eventtype = "4657" and objectname like "HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32"

    Detection Query 5 :

    technologygroup = "EDR" and objectname like "HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32"

    Reference: 

    https://www.rescana.com/post/active-exploitation-alert-head-mare-hacktivists-exploit-trueconf-vulnerabilities-to-trojanize-client-installers-with-pha         


    Tags

    Credential HarvestingWebShellTrojanBackdoorSupply chain attackRussiaMicrosoftMalwareVulnerabilityThreat ActorExploit

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags