Date: 08/10/2026
Severity: High
Summary
The Head Mare hacktivist group exploited two TrueConf Server vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to gain SYSTEM-level access and deploy a web shell.
Attackers then replaced legitimate TrueConf Client installers with trojanized versions containing the PhantomCore and PhantomGraph backdoors, turning the compromise into a supply-chain attack.
PhantomCore enabled reconnaissance, credential theft including LSASS dumping, and C2, while PhantomGraph used Microsoft OneDrive for C2 and both backdoors established persistence as Windows services. The campaign primarily targeted Russian organizations and highlights the risk of trusted software distribution channels being abused to deliver malware.
Indicators of Compromise (IOC) List
Domain/URLs | bright-deals.site cosmetic-deals.store flexish.shop media-hub.today nova-stream.site penzadogshelter.site rinomobile.ink trendy-market.site urbanpixel.store vks.gossopka.forum |
IP Address | 194.87.239.71 194.87.93.153 31.59.102.61 38.244.205.244 81.177.32.12 |
Hashes | 489f43be558b2679284ceabed7adc4f3
4d27b4eb1c5dbb3d8160f29b8119523e
748c9f8cb1065000616204935f96207f
c5a460e4e68a088f6e51b2c6474642ec
dd1fd2b459b97b7d59375cb8383cd19a
|
Regsitry | HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "nova-stream.site" or url like "nova-stream.site" or siteurl like "nova-stream.site" or domainname like "urbanpixel.store" or url like "urbanpixel.store" or siteurl like "urbanpixel.store" or domainname like "flexish.shop" or url like "flexish.shop" or siteurl like "flexish.shop" or domainname like "rinomobile.ink" or url like "rinomobile.ink" or siteurl like "rinomobile.ink" or domainname like "trendy-market.site" or url like "trendy-market.site" or siteurl like "trendy-market.site" or domainname like "penzadogshelter.site" or url like "penzadogshelter.site" or siteurl like "penzadogshelter.site" or domainname like "bright-deals.site" or url like "bright-deals.site" or siteurl like "bright-deals.site" or domainname like "media-hub.today" or url like "media-hub.today" or siteurl like "media-hub.today" or domainname like "vks.gossopka.forum" or url like "vks.gossopka.forum" or siteurl like "vks.gossopka.forum" or domainname like "cosmetic-deals.store" or url like "cosmetic-deals.store" or siteurl like "cosmetic-deals.store" |
Detection Query 2 : | dstipaddress IN ("81.177.32.12","194.87.93.153","31.59.102.61","38.244.205.244","194.87.239.71") or srcipaddress IN ("81.177.32.12","194.87.93.153","31.59.102.61","38.244.205.244","194.87.239.71") |
Detection Query 3 : | md5hash IN ("748c9f8cb1065000616204935f96207f","489f43be558b2679284ceabed7adc4f3","4d27b4eb1c5dbb3d8160f29b8119523e","dd1fd2b459b97b7d59375cb8383cd19a","c5a460e4e68a088f6e51b2c6474642ec")
|
Detection Query 4 : | resoursename = "Windows Security" and eventtype = "4657" and objectname like "HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32" |
Detection Query 5 : | technologygroup = "EDR" and objectname like "HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32" |
Reference:
https://www.rescana.com/post/active-exploitation-alert-head-mare-hacktivists-exploit-trueconf-vulnerabilities-to-trojanize-client-installers-with-pha