ZeroHour
Kaspersky Securelistpublished ()ingested Kaspersky

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

highThreat actor exploited in the wildimportance 67
AI summary · glm-5.3

Head Mare APT exploits unpatched TrueConf server vulnerabilities to deliver PhantomCore and PhantomGraph backdoors to video conference participants.

Kaspersky discovered malicious TrueConf software installers used by the Head Mare APT group to deploy the PhantomCore and PhantomGraph backdoors. The group exploits vulnerabilities in an unpatched TrueConf server to reach targets. Video conference participants are infected via the trojanized installers.

  • Head Mare uses malicious TrueConf installers for malware delivery
  • PhantomCore and PhantomGraph backdoors deployed to target systems
  • Campaign exploits unpatched TrueConf server vulnerabilities
Full article

Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.

This source does not provide full text. Read it at securelist.com.