INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TrueConf Server Exploit Vulnerability Patch Required

| 2026-08-21 08:22 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is increasingly complex, with multiple high-severity attacks targeting Russian organizations across various sectors. A critical missing authentication security flaw (CVE-2026-72529) allows attackers to remotely execute arbitrary scripts on unpatched servers, while another vulnerability (CVE-2026-72530) enables high-complexity code injection attacks to gain remote code execution. These exploits have been linked to the Head Mare hacktivist group, which has been using them since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware. The TrueConf Server flaw (CVE-2026) is also being exploited by Chinese threat actors in zero-day attacks dubbed "Operation True Chaos." The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to prioritize patching these vulnerabilities, which operate inside an organization's local network.
Technical Mitigations AI-generated
* Implement a secure patching strategy for TrueConf Server, including: + Regularly updating and patching the software to ensure all known vulnerabilities are addressed. + Using a vulnerability scanning tool to identify potential issues before they become exploits. + Prioritizing patches based on severity and criticality to minimize downtime. * Conduct thorough risk assessments and threat modeling for TrueConf Server deployments, including: + Identifying potential attack vectors and mitigating factors. + Developing incident response plans to address potential breaches. + Implementing access controls and authentication mechanisms to restrict unauthorized access. * Educate users on the importance of secure coding practices when developing applications that interact with TrueConf Server, including: + Using secure coding guidelines and best practices for code generation and injection attacks. + Avoiding high-complexity code injection attacks by using secure input validation and sanitization techniques. + Regularly updating dependencies and libraries to ensure they are patched against known vulnerabilities.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation True ChaosOperation True Chaos HavocHavoc CVE-2026-3502CVE-2026-3502 CVE-2026-72530CVE-2026-72530 CVE-2026-72529CVE-2026-72529
Target & Sectors
APAC APAC governmentgovernment educationeducation transportationtransportation technologytechnology energyenergy logisticslogistics
Incident Timeline
‎September 2025
Threat actors used a BDU:2025-10116 vulnerability in TrueConf Server to replace client installers with PhantomCore.
organisation PHP
general_metric 10116 vulnerabilities
‎April 2026
Hackers exploited a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502.
vulnerability CVE-2026-3502
campaign Operation True Chaos
organisation Check Point Research
source_region China
organisation CheckPoint Research
‎at least May 2026
Threat actors exploited TrueConf Server flaws to replace client installers with PhantomCore.
industry Government
target_region Russian Federation
industry Energy
industry Education
industry Logistics
‎June 18, 2026
Threat actors exploited vulnerabilities in TrueConf Server to replace client installers with PhantomCore.
tactic T1584.004 - Server
infrastructure 5.3.9
infrastructure 5.4.9
infrastructure 5.5.5
‎June 18
Threat actors exploited TrueConf Server flaws to replace client installers with PhantomCore in versions 5.3.9, 5.4.9, and 5.5.5 released on June 18.
infrastructure 5.3.9
infrastructure 5.4.9
infrastructure 5.5.5
‎at least July 2026
Threat actors exploited CVE-2026-72529 and CVE-2026-72530 vulnerabilities in TrueConf Server to replace client installers with PhantomCore.
vulnerability CVE-2026-72529
vulnerability CVE-2026-72530
attribution Kaspersky
general_metric 72530 CVE-2026
‎July 2026
Russian cybersecurity vendors detected the attacks in July 2026.
source_region Russian Federation
‎BDU:2025-10114
Threat actors exploited three vulnerabilities in the TrueConf Server software to replace client installers with PhantomCore.
organisation PHP
general_metric 10116 vulnerabilities
‎BDU:2025-10115
Threat actors used a BDU:2025-10115 vulnerability in the TrueConf Server software to replace client installers with PhantomCore.
organisation PHP
general_metric 10116 vulnerabilities
‎2026/08/21
Attackers connected to the TrueConf server on TCP port 4307, which is open by default.
organisation TCP
infrastructure 5.3
infrastructure 5.3.9
infrastructure 5.4
infrastructure 5.4.9
infrastructure 5.5
infrastructure 5.5.5
organisation Microsoft Teams
organisation LAN
organisation Kaspersky
organisation TrueConf Client
organisation CheckPoint
organisation APT
organisation sina[.]com
organisation the University of Science and Technology of China
organisation The Blue Report 2026
infrastructure Windows
organisation SysReadSvc.dll
organisation PhantomGraph
organisation DLL
organisation Microsoft OneDrive
organisation SSH
organisation HelloNet
organisation EDR
organisation HelloProxy
organisation HelloInjector
organisation HelloCleaner
organisation the Local Security Authority Subsystem Service
‎August 23, 2026
Threat actors exploited the TrueConf Server flaw CVE-2026-72529 to replace client installers with PhantomCore.
vulnerability CVE-2026-72529
vulnerability CVE-2026-72530
‎September 2nd
Threat actors exploited a vulnerability in the TrueConf Server to replace client installers with PhantomCore.
vulnerability CVE-2026-72529
vulnerability CVE-2026-72530
‎September 3
Threat actors exploited TrueConf Server flaws to replace client installers with PhantomCore.
attribution KEV
attribution FCEB
attribution U.S. Federal Civilian Executive Branch
Tactical Metrics
Metrics
infrastructure
‎5.3
Software Version
Metrics
infrastructure
‎5.3.9
Software Version
Metrics
infrastructure
‎5.4
Software Version
Metrics
infrastructure
‎5.4.9
Software Version
Metrics
infrastructure
‎5.5
Software Version
Metrics
infrastructure
‎5.5.5
Software Version
Metrics
infrastructure
‎Windows
Affected Product