Hackers Exploit TrueConf Servers to Deploy Malicious Backdoors
Head Mare hackers exploit TrueConf servers to inject malicious client installers with backdoors, compromising Russian organizations in various sectors.
Intelligence analysis by Qwen 2.5 (3B)

Hacking group Head Mare uses vulnerabilities in TrueConf video conferencing servers to deploy malware. The attack affects multiple sectors including instrumentation and transportation.
Hackers found a way to trick video conferencing software into giving them control. They used fake updates to make people download bad stuff that lets them spy on computers.
Analysis
Head Mare Exploits TrueConf Servers
Head Mare, a known hacking group, has been targeting TrueConf servers to inject malicious client installers. The attack leverages vulnerabilities in TrueConf Server versions before 5.3.9, 5.4.9, and 5.5.5.
Vulnerabilities Exploited
The attackers used TCP port 4307 without authentication to connect to the target servers. They exploited internal Kaspersky vulnerabilities (KLCERT-26-057 and KLCERT-26-058) to execute a malicious script within TrueConf's isolated environment.
Impact on Organizations
TrueConf is widely used in Russia, particularly by enterprises and government sectors. The attack affects multiple industries including instrumentation, electronics, transportation, energy, IT, and software development. Even organizations not using the TrueConf server can be affected if their employees connect to compromised servers.
Initial Access Methods
Head Mare employs various methods for initial access, such as phishing, exploiting public-facing web servers, and contractor access.
Security Measures Needed
Security teams often fail to detect successful attacks; only 14% of them are alerted. The article suggests that conducting regular breach and attack simulation tests can improve detection rates.
Future Threats
The article mentions the potential for future threats from APT groups like Head Mare, emphasizing the need for continuous security monitoring and robust defense strategies.
Key points
- Head Mare uses vulnerabilities in TrueConf servers to inject malicious client installers
- The attack affects multiple sectors including instrumentation, electronics, transportation, energy, IT, and software development
- Security teams often fail to detect successful attacks
By improving detection methods, like using more advanced security tools and testing systems regularly, we can catch these attacks earlier and stop the hackers from doing damage.
If security teams don't improve their practices or if attackers find new ways to hide their actions, this kind of attack could become even more common and harder to detect.



