PhantomGraph is a Windows backdoor associated with the Head Mare threat actor and used in campaigns targeting Russian organizations, including entities in instrumentation, electronics, transportation, energy, IT, and software development. It has been observed in intrusions involving compromised TrueConf servers, where attackers first gained server-side access through exploitation and web-shell deployment, then deployed PhantomGraph alongside PhantomCore and, in some cases, distributed trojanized TrueConf client installers to downstream users.
PhantomGraph is composed of two DLL modules that split command handling and execution functions. One module receives operator tasking through Microsoft OneDrive and returns execution results through the same cloud channel, while the second parses and executes the received commands and stores the output. This use of a legitimate cloud service helps blend malicious traffic with normal cloud activity. Reported post-compromise use includes host reconnaissance, credential-access activity such as LSASS memory dumping, and support for reverse-tunnel operations. The malware has also been installed as Windows services to maintain persistence on infected systems. Code overlap with PhantomCore links PhantomGraph to the broader Head Mare malware arsenal.
Operationally, PhantomGraph functions as a post-exploitation backdoor for remote command execution and result exfiltration on compromised Windows hosts. In the observed TrueConf-related activity, it formed part of a broader intrusion set that included exploitation of public-facing applications, web-shell access, persistence establishment, credential theft, and follow-on movement within victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore and PhantomGraph
30 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server... The attackers connect to the TrueConf server without prior authorization via port 4307/TCP... attackers call a server function to transmit a malicious script and execute it on the server.
The attackers distribute their backdoors using various methods, including phishing, exploiting public web servers, or through a subcontractor.
C:\Windows\System32\inetsrv\share\input_*.txt C:\Windows\System32\inetsrv\share\output_*.txt %TEMP%\cmd_cmd_*.bat
Head Mare, now assessed as an APT group, exploited two vulnerabilities in unpatched TrueConf video conferencing servers to achieve SYSTEM-level code execution and deploy a web shell.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
To escape the isolated environment, attackers exploit a second vulnerability... Exploiting this vulnerability allows them to bypass the restrictions of the isolated environment and proceed to execute commands in the context of the operating system... with the privileges of the NT AUTHORITY\SYSTEM account.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
The attackers used an account on Microsoft OneDrive cloud storage as their command-and-control (C2) server.
Exfiltration and C2 communications were conducted over both custom malicious domains and IP addresses, as well as via OneDrive cloud storage.
PhantomGraph (SysExcSvc.dll and SysReadSvc.dll) is another backdoor that communicates with attacker infrastructure via Microsoft OneDrive, blending malicious traffic with legitimate cloud storage activity.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware payload delivered in the TrueConf server intrusion campaign attributed to Head Mare.
Backdoor composed of SysExcSvc.dll and SysReadSvc.dll modules. It uses Microsoft OneDrive as C2, executes attacker commands, stores results, and persists as Windows services.
A two-module backdoor in the Head Mare arsenal. SysExcSvc.dll handles command receipt and result transmission using a Microsoft OneDrive account as C2, while SysReadSvc.dll reads commands, executes them via batch files, and stores results. Persistence is established by installing the modules as Windows services.
A separate backdoor used by Head Mare that operates via a OneDrive account.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.