PhantomCore is a Windows backdoor associated with the Head Mare threat group. It enables remote execution of arbitrary commands, giving attackers control over infected systems. In observed TrueConf infections, the payload was deployed as a DLL and established persistence through COM hijacking, registering the malicious library for automatic execution.
In a July 2026 campaign, Head Mare distributed PhantomCore through trojanized TrueConf Client installers hosted on compromised enterprise video-conferencing servers. The attackers chained two TrueConf Server vulnerabilities to obtain privileged code execution, deployed a web shell, and replaced legitimate client distribution packages with malicious versions. These packages retained the legitimate client's installation functionality while also installing PhantomCore and lacked valid vendor digital signatures. Conference participants received the infected software as a client download or update, allowing compromise to extend to employees of external organizations joining meetings on affected servers.
The campaign targeted Russian organizations in instrumentation, electronics, transportation, energy, IT, and software development. PhantomCore was used alongside other Head Mare tools, including the separate PhantomGraph backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
With an initial foothold on the server, attackers then chained the second vulnerability, CVE-2026-72530, which enabled them to escape the isolated environment and execute arbitrary code on the server with system privileges. | The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.”
Kaspersky discovered that Head Mare attackers were using CVE-2026-72529 to gain initial access to TrueConf servers; the vulnerability enables remote, unauthorized access over the network via port 4307/TCP and execution of arbitrary scripts within an isolated environment by calling an undocumented function. | The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
В свежей кампании Head Mare проэксплуатировали цепочку уязвимостей в сервере видеоконференций TrueConf и заменили оригинальные инсталляторы клиента TrueConf на зараженные версии, устанавливающие в систему вредоносное ПО PhantomCore.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
An unauthorized attacker can connect to TrueConf server versions 5.3.X before 5.3.9, 5.4.X before 5.4.9, 5.5.X before 5.5.5 ... via port 4307/TCP ... and execute a malicious script on the server by calling an undocumented function.
The attackers also replaced the TrueConf client distribution file, trueconf_windows_client_x64.exe, with a malicious version causing users who joined a TrueConf meeting on a compromised server to receive a prompt to install the trojanized version.
[They] replace the legitimate TrueConf Client installer on the server with a malicious version containing the PhantomCore backdoor. When members of an organization connect to a compromised local TrueConf server, they can receive the trojanized installer as an update.
all subsequent actions are carried out by remotely running PowerShell scripts via a web shell.
The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.”
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
To automatically launch the malware after system startup, a registry key is created: HKEY_CURRENT_USER\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32
This enables them to replace the file C:/Program Files/TrueConf Server/httpconf/site/public/js/locale.php with a malicious web shell program... Attackers use the web shell to install a backdoor-type malicious program on the server
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
Head Mare leveraged this access to replace a TrueConf file, locale.php, with a web shell and install a backdoor, enabling further command execution
The second vulnerability let attackers break out of an isolated execution environment and run code with NT AUTHORITY\SYSTEM privileges, granting full control of the server.
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
Head Mare leveraged this access to replace a TrueConf file, locale.php, with a web shell and install a backdoor, enabling further command execution
as well as delete records from the TrueConf event logs related to the exploit’s operation.
This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database
90 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor embedded in trojanized TrueConf Client installers and distributed through compromised on-premise TrueConf servers.
A malware payload delivered via a trojanized TrueConf client installer that gives attackers arbitrary command execution and effectively full control over infected systems.
A backdoor delivered via a trojanized TrueConf Windows client installer after attackers compromised TrueConf servers, creating a supply-chain-style risk for meeting participants downloading the client from hacked infrastructure.
Malware deployed via trojanized TrueConf client installers after exploitation of TrueConf server vulnerabilities. It is associated with Head Mare intrusions and the campaign context indicates destructive activity, including file-encrypting behavior and ransom demands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.