The pro-Ukrainian hacktivist group Head Mare is conducting a sophisticated supply-chain attack by exploiting vulnerabilities in TrueConf video conferencing servers. According to research from Kaspersky, the group is compromising unpatched servers to replace legitimate TrueConf client installers with trojanized versions. These malicious installers, when downloaded and run by users, deploy backdoors including PhantomCore RAT and PhantomGraph. The campaign, observed in July 2026, has targeted Russian organizations across multiple sectors, demonstrating the group's growing technical capabilities and its focus on disruptive attacks.
The attack targets organizations in Russia using on-premise TrueConf Server instances. Head Mare's operation leverages a chain of two vulnerabilities (KLCERT-26-057 and KLCERT-26-058) in older versions of the software to achieve full system control and then poison the software distribution mechanism.
Attack Chain:
4307. (T1190 - Exploit Public-Facing Application)KLCERT-26-057 and KLCERT-26-058) to escape a sandbox environment and execute commands with NT AUTHORITY\SYSTEM privileges. (T1068 - Exploitation for Privilege Escalation)locale.php file, giving the attackers persistent remote access to the server. (T1505.003 - Web Shell)T1195.002 - Compromise Software Supply Chain)KLCERT-26-057 and KLCERT-26-058 (No CVEs assigned). These allow for sandbox escape and arbitrary code execution.A key indicator of this attack is that the malicious installer is not digitally signed, whereas the legitimate TrueConf installer is. This provides a crucial verification point for security-conscious users.
This campaign has a significant impact on the targeted Russian organizations.
locale.php4307Security teams can hunt for signs of this activity:
...\web\locale\locale.php4307 from unknown or suspicious IP addresses.TrueConf-Client-7.5.1.exe (or similar)locale.php. Use System File Analysis (D3-SFA).CISA adds TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to KEV, confirming active exploitation by Head Mare for unauthenticated RCE.
The primary mitigation is to update TrueConf Server to a patched version (5.3.9, 5.4.9, 5.5.5 or newer).
Enforce policies that verify software digital signatures before installation. Alert on or block unsigned executables.
Implement file integrity monitoring to detect unauthorized changes to critical application files like 'locale.php'.
Restrict access to the TrueConf server's management ports from the internet, allowing connections only from trusted IP ranges.
TrueConf releases patches for the exploited vulnerabilities.
Kaspersky observes the Head Mare campaign actively exploiting the vulnerabilities.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.