Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Head Mare APT exploits unpatched TrueConf server vulnerabilities to deliver PhantomCore and PhantomGraph backdoors to video conference participants.
Kaspersky discovered malicious TrueConf software installers used by the Head Mare APT group to deploy the PhantomCore and PhantomGraph backdoors. The group exploits vulnerabilities in an unpatched TrueConf server to reach targets. Video conference participants are infected via the trojanized installers.