INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TrueConf Server Exploit Vulnerability Patch Required
| 2026-08-21 08:22 CRITICAL HIGHExecutive Summary AI-generated
The threat landscape is increasingly complex, with multiple high-severity attacks targeting Russian organizations across various sectors. A critical missing authentication security flaw (CVE-2026-72529) allows attackers to remotely execute arbitrary scripts on unpatched servers, while another vulnerability (CVE-2026-72530) enables high-complexity code injection attacks to gain remote code execution. These exploits have been linked to the Head Mare hacktivist group, which has been using them since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware.
The TrueConf Server flaw (CVE-2026) is also being exploited by Chinese threat actors in zero-day attacks dubbed "Operation True Chaos." The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to prioritize patching these vulnerabilities, which operate inside an organization's local network.
Technical Mitigations AI-generated
* Implement a secure patching strategy for TrueConf Server, including:
+ Regularly updating and patching the software to ensure all known vulnerabilities are addressed.
+ Using a vulnerability scanning tool to identify potential issues before they become exploits.
+ Prioritizing patches based on severity and criticality to minimize downtime.
* Conduct thorough risk assessments and threat modeling for TrueConf Server deployments, including:
+ Identifying potential attack vectors and mitigating factors.
+ Developing incident response plans to address potential breaches.
+ Implementing access controls and authentication mechanisms to restrict unauthorized access.
* Educate users on the importance of secure coding practices when developing applications that interact with TrueConf Server, including:
+ Using secure coding guidelines and best practices for code generation and injection attacks.
+ Avoiding high-complexity code injection attacks by using secure input validation and sanitization techniques.
+ Regularly updating dependencies and libraries to ensure they are patched against known vulnerabilities.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation True ChaosOperation True Chaos
HavocHavoc
CVE-2026-3502CVE-2026-3502
CVE-2026-72530CVE-2026-72530
CVE-2026-72529CVE-2026-72529
Target & Sectors
APAC
APAC
governmentgovernment
educationeducation
transportationtransportation
technologytechnology
energyenergy
logisticslogistics
Incident Timeline
September 2025
Threat actors used a BDU:2025-10116 vulnerability in TrueConf Server to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
organisation
PHP
Earlier this April, Positive Technologies
disclosed
that three vulnerabilities in the software (BDU:2025-10114, BDU:2025-10115, and BDU-2025-10116) were abused by the group since September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution.
general_metric
10116 vulnerabilities
Earlier this April, Positive Technologies
disclosed
that three vulnerabilities in the software (BDU:2025-10114, BDU:2025-10115, and BDU-2025-10116) were abused by the group since September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution.
April 2026
Hackers exploited a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-3502
In April 2026,
Check Point Research also reported
that hackers were targeting another TrueConf flaw (CVE-2026-3502) in zero-day attacks dubbed "Operation True Chaos" and linked to Chinese threat actors, compromising users via trojanized client updates.
In April 2026,
CheckPoint Research reported
that hackers were targeting a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502, compromising users via trojanized client updates.
campaign
Operation True Chaos
In April 2026,
Check Point Research also reported
that hackers were targeting another TrueConf flaw (CVE-2026-3502) in zero-day attacks dubbed "Operation True Chaos" and linked to Chinese threat actors, compromising users via trojanized client updates.
organisation
Check Point Research
In April 2026,
Check Point Research also reported
that hackers were targeting another TrueConf flaw (CVE-2026-3502) in zero-day attacks dubbed "Operation True Chaos" and linked to Chinese threat actors, compromising users via trojanized client updates.
source_region
China
In April 2026,
Check Point Research also reported
that hackers were targeting another TrueConf flaw (CVE-2026-3502) in zero-day attacks dubbed "Operation True Chaos" and linked to Chinese threat actors, compromising users via trojanized client updates.
organisation
CheckPoint Research
In April 2026,
CheckPoint Research reported
that hackers were targeting a zero-day arbitrary file execution flaw in TrueConf, tracked as CVE-2026-3502, compromising users via trojanized client updates.
at least May 2026
Threat actors exploited TrueConf Server flaws to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
industry
Government
The development comes weeks after Kaspersky said it discovered a new advanced persistent threat (APT)-style attack that has been ongoing since at least May 2026 using previously unreported tooling, primarily by taking advantage of the update mechanism for the ViPNet product suite to target Russian government, energy, transport, education, and logistics sectors.
target_region
Russian Federation
The development comes weeks after Kaspersky said it discovered a new advanced persistent threat (APT)-style attack that has been ongoing since at least May 2026 using previously unreported tooling, primarily by taking advantage of the update mechanism for the ViPNet product suite to target Russian government, energy, transport, education, and logistics sectors.
industry
Energy
The development comes weeks after Kaspersky said it discovered a new advanced persistent threat (APT)-style attack that has been ongoing since at least May 2026 using previously unreported tooling, primarily by taking advantage of the update mechanism for the ViPNet product suite to target Russian government, energy, transport, education, and logistics sectors.
industry
Education
The development comes weeks after Kaspersky said it discovered a new advanced persistent threat (APT)-style attack that has been ongoing since at least May 2026 using previously unreported tooling, primarily by taking advantage of the update mechanism for the ViPNet product suite to target Russian government, energy, transport, education, and logistics sectors.
industry
Logistics
The development comes weeks after Kaspersky said it discovered a new advanced persistent threat (APT)-style attack that has been ongoing since at least May 2026 using previously unreported tooling, primarily by taking advantage of the update mechanism for the ViPNet product suite to target Russian government, energy, transport, education, and logistics sectors.
June 18, 2026
Threat actors exploited vulnerabilities in TrueConf Server to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.
infrastructure
5.3.9
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.
infrastructure
5.4.9
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.
infrastructure
5.5.5
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.
June 18
Threat actors exploited TrueConf Server flaws to replace client installers with PhantomCore in versions 5.3.9, 5.4.9, and 5.5.5 released on June 18.
Click on any entity below to view its context and source!
infrastructure
5.3.9
The vendor fixed them in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18.
infrastructure
5.4.9
The vendor fixed them in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18.
infrastructure
5.5.5
The vendor fixed them in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18.
at least July 2026
Threat actors exploited CVE-2026-72529 and CVE-2026-72530 vulnerabilities in TrueConf Server to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-72529
While CISA didn't share details on these attacks, cybersecurity company Kaspersky said the Head Mare hacktivist group
has been exploiting CVE-2026-72529 and CVE-2026-72530
since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware.
vulnerability
CVE-2026-72530
While CISA didn't share details on these attacks, cybersecurity company Kaspersky said the Head Mare hacktivist group
has been exploiting CVE-2026-72529 and CVE-2026-72530
since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware.
attribution
Kaspersky
While CISA didn't share details on these attacks, cybersecurity company Kaspersky said the Head Mare hacktivist group
has been exploiting CVE-2026-72529 and CVE-2026-72530
since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware.
general_metric
72530 CVE-2026
While CISA didn't share details on these attacks, cybersecurity company Kaspersky said the Head Mare hacktivist group
has been exploiting CVE-2026-72529 and CVE-2026-72530
since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware.
July 2026
Russian cybersecurity vendors detected the attacks in July 2026.
Click on any entity below to view its context and source!
source_region
Russian Federation
Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.
BDU:2025-10114
Threat actors exploited three vulnerabilities in the TrueConf Server software to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
organisation
PHP
Earlier this April, Positive Technologies
disclosed
that three vulnerabilities in the software (BDU:2025-10114, BDU:2025-10115, and BDU-2025-10116) were abused by the group since September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution.
general_metric
10116 vulnerabilities
Earlier this April, Positive Technologies
disclosed
that three vulnerabilities in the software (BDU:2025-10114, BDU:2025-10115, and BDU-2025-10116) were abused by the group since September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution.
BDU:2025-10115
Threat actors used a BDU:2025-10115 vulnerability in the TrueConf Server software to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
organisation
PHP
Earlier this April, Positive Technologies
disclosed
that three vulnerabilities in the software (BDU:2025-10114, BDU:2025-10115, and BDU-2025-10116) were abused by the group since September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution.
general_metric
10116 vulnerabilities
Earlier this April, Positive Technologies
disclosed
that three vulnerabilities in the software (BDU:2025-10114, BDU:2025-10115, and BDU-2025-10116) were abused by the group since September 2025 to deliver PHP web shells and malicious payloads for information theft and command execution.
2026/08/21
Attackers connected to the TrueConf server on TCP port 4307, which is open by default.
Click on any entity below to view its context and source!
organisation
TCP
CVE-2026-72529 is a remote code execution vulnerability in TrueConf Server that allows an unauthenticated remote attacker with network access to TCP port 4307 to execute arbitrary scripts by calling an undocumented function.
The attack chain is as follows -
Attackers connect to the TrueConf server on TCP port 4307, which is open by default.
They found that Head Mare hackers used TCP port 4307, which is open by default, to connect to the target TrueConf server without authentication.
infrastructure
5.3
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
infrastructure
5.3.9
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
infrastructure
5.4
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
infrastructure
5.4.9
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
infrastructure
5.5
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
infrastructure
5.5.5
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
organisation
Microsoft Teams
TrueConf Server is designed for secure corporate messaging and video conferencing and, unlike cloud-based software like Zoom or Microsoft Teams, it operates inside an organization's local network (LAN).
organisation
LAN
TrueConf Server is designed for secure corporate messaging and video conferencing and, unlike cloud-based software like Zoom or Microsoft Teams, it operates inside an organization's local network (LAN).
organisation
Kaspersky
According to Kaspersky, multiple Head Mare campaigns targeted Russian organizations across various industry sectors, including transportation, energy, IT, electronics, and software development.
The web shell, per Kaspersky, has been leveraged to collect data on the IT infrastructure, gain privileged access to the TrueConf database, and ultimately substitute the original TrueConf Client distribution with an infected version containing PhantomCore.
Researchers at cybersecurity company Kaspersky discovered the attack in July.
organisation
TrueConf Client
The web shell, per Kaspersky, has been leveraged to collect data on the IT infrastructure, gain privileged access to the TrueConf database, and ultimately substitute the original TrueConf Client distribution with an infected version containing PhantomCore.
Kaspersky reports that Head Mare uses a web shell to collect sensitive information from the victim’s environment, access the TrueConf database, and replace the legitimate TrueConf Client installer hosted on the server with a malicious version that contains the PhantomCore backdoor.
organisation
CheckPoint
CheckPoint named the campaign ‘Operation True Chaos,’ and tentatively attributed it to Chinese threat actors behind the Havoc implant, which was used in these attacks.
organisation
APT
The activities have been tied to an unknown Chinese-speaking APT with low confidence, citing a reference to the Chinese website sina[.]com and an open-source software download mirror ("mirrors.ustc.edu[.]cn") hosted by the University of Science and Technology of China.
organisation
sina[.]com
The activities have been tied to an unknown Chinese-speaking APT with low confidence, citing a reference to the Chinese website sina[.]com and an open-source software download mirror ("mirrors.ustc.edu[.]cn") hosted by the University of Science and Technology of China.
organisation
the University of Science and Technology of China
The activities have been tied to an unknown Chinese-speaking APT with low confidence, citing a reference to the Chinese website sina[.]com and an open-source software download mirror ("mirrors.ustc.edu[.]cn") hosted by the University of Science and Technology of China.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
infrastructure
Windows
What's more, the web shell serves as a conduit for another backdoor codenamed PhantomGraph that shares some level of code overlap with PhantomCore and includes two DLL modules -
"SysExcSvc.dll," for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
"SysReadSvc.dll," for parsing the commands received by the first module, executing it, and storing the results
"To establish a persistent presence in the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services," Kaspersky said.
organisation
SysReadSvc.dll
What's more, the web shell serves as a conduit for another backdoor codenamed PhantomGraph that shares some level of code overlap with PhantomCore and includes two DLL modules -
"SysExcSvc.dll," for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
"SysReadSvc.dll," for parsing the commands received by the first module, executing it, and storing the results
"To establish a persistent presence in the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services," Kaspersky said.
organisation
PhantomGraph
What's more, the web shell serves as a conduit for another backdoor codenamed PhantomGraph that shares some level of code overlap with PhantomCore and includes two DLL modules -
"SysExcSvc.dll," for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
"SysReadSvc.dll," for parsing the commands received by the first module, executing it, and storing the results
"To establish a persistent presence in the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services," Kaspersky said.
The exploited vulnerabilities allowed the attacker to execute arbitrary code with the highest level of privileges and deploy the PhantomCore and PhantomGraph backdoors.
organisation
DLL
What's more, the web shell serves as a conduit for another backdoor codenamed PhantomGraph that shares some level of code overlap with PhantomCore and includes two DLL modules -
"SysExcSvc.dll," for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
"SysReadSvc.dll," for parsing the commands received by the first module, executing it, and storing the results
"To establish a persistent presence in the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services," Kaspersky said.
Additionally, Head Mare deploys PhantomGraph, a separate backdoor consisting of two DLL files (SysExcSvc.dll and SysReadSvc.dll) that accept commands via a Microsoft OneDrive account, execute them, and return the results.
organisation
Microsoft OneDrive
What's more, the web shell serves as a conduit for another backdoor codenamed PhantomGraph that shares some level of code overlap with PhantomCore and includes two DLL modules -
"SysExcSvc.dll," for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
"SysReadSvc.dll," for parsing the commands received by the first module, executing it, and storing the results
"To establish a persistent presence in the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services," Kaspersky said.
Additionally, Head Mare deploys PhantomGraph, a separate backdoor consisting of two DLL files (SysExcSvc.dll and SysReadSvc.dll) that accept commands via a Microsoft OneDrive account, execute them, and return the results.
organisation
SSH
"
In addition, the threat actors have been found to launch an SSH reverse tunnel, take a memory dump of the "lsass.exe" process, and collect general system information using commands like hostname and whoami.
The malware also runs commands for reconnaissance activity, such as
hostname
and
whoami
, and starts a reverse SSH tunnel.
organisation
HelloNet
The HelloNet attack involves the execution of a malicious DLL ("wtsapi32.dll") that masquerades as a legitimate file associated with the ViPNet suite update system.
organisation
EDR
"We believe the attackers deliberately split this malware into two components to make it harder for EDR tools to detect.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
HelloProxy
ViPNet Update Mechanism Hijacked to Deploy HelloInjector and HelloProxy
organisation
HelloInjector
If found, HelloInjector loads and executes the malicious payload that's stored in its body in plaintext.
organisation
HelloCleaner
Besides taking steps to interfere with the normal functioning of security solutions operating in user mode for filtering network connections, it serves as a loader for two components -
HelloExecutor, to execute commands on the infected system and launch an SSH tunnel to attacker infrastructure
HelloCleaner, to clean ViPNet software log files and erase forensic trail
Also discovered in one of the infected systems is a Rust implant named HelloBackdoor that can enable file uploads and downloads to and from the C2 server.
organisation
the Local Security Authority Subsystem Service
Observed attacker activity through PhantomGraph included dumping the memory of the Local Security Authority Subsystem Service (LSASS) process to exfiltrate credentials.
August 23, 2026
Threat actors exploited the TrueConf Server flaw CVE-2026-72529 to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-72529
CISA orders federal agencies to fix the flaw CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2nd.
vulnerability
CVE-2026-72530
CISA orders federal agencies to fix the flaw CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2nd.
September 2nd
Threat actors exploited a vulnerability in the TrueConf Server to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-72529
CISA orders federal agencies to fix the flaw CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2nd.
vulnerability
CVE-2026-72530
CISA orders federal agencies to fix the flaw CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2nd.
September 3
Threat actors exploited TrueConf Server flaws to replace client installers with PhantomCore.
Click on any entity below to view its context and source!
attribution
KEV
On Thursday, CISA
added the two flaws
to its
KEV catalog
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks, by September 3.
attribution
FCEB
On Thursday, CISA
added the two flaws
to its
KEV catalog
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks, by September 3.
attribution
U.S. Federal Civilian Executive Branch
On Thursday, CISA
added the two flaws
to its
KEV catalog
and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks, by September 3.
Tactical Metrics
Metrics
infrastructure
5.3
Software Version
Click for context!
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
Metrics
infrastructure
5.3.9
Software Version
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The vendor fixed them in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18.
Metrics
infrastructure
5.4
Software Version
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
Metrics
infrastructure
5.4.9
Software Version
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The vendor fixed them in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18.
Metrics
infrastructure
5.5
Software Version
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
Metrics
infrastructure
5.5.5
Software Version
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.
TrueConf vulnerabilities
The two flaws Kaspersky saw leveraged in attacks affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions.
The vendor fixed them in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18.
Metrics
infrastructure
Windows
Affected Product
What's more, the web shell serves as a conduit for another backdoor codenamed PhantomGraph that shares some level of code overlap with PhantomCore and includes two DLL modules -
"SysExcSvc.dll," for receiving commands and exfiltrating their results back to Microsoft OneDrive cloud storage that's used as command-and-control (C2)
"SysReadSvc.dll," for parsing the commands received by the first module, executing it, and storing the results
"To establish a persistent presence in the system, the attackers execute a Base64-encoded PowerShell command that installs SysExcSvc.dll and SysReadSvc.dll as Windows services," Kaspersky said.
Intelligence Sources
BleepingComputer
2026-08-08
The Hacker News
2026-08-10
Security Affairs
2026-08-21
BleepingComputer
2026-08-21
CISA orders feds to patch actively exploited TrueConf Server flaws
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-22T06:33
Comprehensive Tactical Telemetry
Highly Correlated Entities
24x
organisation
Identified Entity
TCP
entity
13x
timeline
Temporal Reference
August 23, 2026
date
13x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
6x
industry
Targeted Sector
Government
sector
6x
infrastructure
Software Version
5.3
version
3x
vulnerability
Exploited CVE
CVE-2026-72529
cve
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
vulnerability
CVSS Score
9
score
2x
target region
Target Country
Russian Federation
country
2x
source region
Origin Country
China
country
2x
general metric
Klcert-26
57
klcert-26
2x
general metric
%
54
%
Contextual Telemetry
Context Block
9 METRICS
general metric
Tcp Port
4,307
tcp port
general metric
Cve-2026
72,530
cve-2026
campaign
Campaign
Operation True Chaos
operation
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
target region
Target Region
APAC
region
malware
Malware Payload
Havoc
tool
infrastructure
Affected Product
Windows
software
general metric
Vulnerabilities
10,116
vulnerabilities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.