PhantomCore is a Windows backdoor associated with the Head Mare threat actor and used in campaigns targeting Russian organizations across sectors including instrumentation, electronics, transportation, energy, IT, software development, government, logistics, finance, and industry. It has been delivered through multiple intrusion paths, including trojanized TrueConf Client installers distributed from compromised TrueConf servers, phishing campaigns using archive-based lures and shortcut files, and activity involving NTLM-hash theft workflows.
In the July 2026 TrueConf supply-chain-style campaign, attackers exploited a chain of vulnerabilities in exposed TrueConf Server instances to gain SYSTEM-level code execution, deploy a web shell, access the TrueConf database, and replace legitimate client installers with malicious unsigned versions embedding PhantomCore. This created downstream exposure for conference participants and partner organizations that downloaded the client from compromised servers. In that activity, PhantomCore functioned as a DLL-based backdoor providing command-and-control, system reconnaissance, credential theft, and persistence. Reported post-compromise behavior included reconnaissance commands, dumping LSASS memory to obtain credentials, and support for broader follow-on compromise inside victim environments.
PhantomCore has also appeared in phishing operations attributed to Head Mare. In one observed campaign, password-protected archives containing disguised shortcut files launched a PowerShell-based loader, opened decoy content, established persistence through COM hijacking, and installed a PhantomCore variant also referred to as PhantomDL. That variant was described as a C++ backdoor whose primary purpose was to provide a remote command shell and communicate with command-and-control infrastructure using JSON over HTTP POST requests. Related operations also used reverse SSH tunneling utilities to proxy traffic into victim networks.
Across reporting, PhantomCore is consistently characterized as a custom Head Mare backdoor or remote-access implant rather than commodity malware. It is linked to credential theft, reconnaissance, persistence, and post-exploitation activity, and has been used both as a directly delivered implant and as part of broader multi-stage intrusions involving additional malware such as PhantomGraph.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers used the compromised server to collect infrastructure data, access the TrueConf database, and replace legitimate TrueConf Client installers with trojanized versions containing the PhantomCore backdoor, potentially compromising video conference participants.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server... The attackers connect to the TrueConf server without prior authorization via port 4307/TCP... attackers call a server function to transmit a malicious script and execute it on the server.
...and replace legitimate TrueConf Client installers with trojanized versions containing the PhantomCore backdoor, potentially compromising video conference participants.
substitution de l’installateur TrueConf Client par une version infectée contenant PhantomCore
C:\Windows\System32\inetsrv\share\input_*.txt C:\Windows\System32\inetsrv\share\output_*.txt %TEMP%\cmd_cmd_*.bat
Head Mare, now assessed as an APT group, exploited two vulnerabilities in unpatched TrueConf video conferencing servers to achieve SYSTEM-level code execution and deploy a web shell.
Once they have gained elevated privileges, attackers replace the file …\public\js\locale.php with a web shell, which can be used for subsequent remote control of the compromised server.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
To escape the isolated environment, attackers exploit a second vulnerability... Exploiting this vulnerability allows them to bypass the restrictions of the isolated environment and proceed to execute commands in the context of the operating system... with the privileges of the NT AUTHORITY\SYSTEM account.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
90 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor delivered via trojanized TrueConf Client installers after compromise of unpatched TrueConf servers, enabling downstream compromise of video conference participants.
Backdoor malware used by Head Mare and delivered via trojanized TrueConf client installers. It establishes persistence via a CLSID registry key and provides attacker access on compromised systems.
A backdoor used by the Head Mare group that was delivered via trojanized TrueConf client installers after compromise of TrueConf servers. It establishes persistence via a CLSID InprocServer32 registry key and provides post-compromise access on infected systems.
A backdoor delivered through trojanized TrueConf client installers after attackers compromise vulnerable TrueConf servers, enabling infection of users who update their client.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.