TrueConf Servers Hijacked to Deliver Backdoor-Laced Client Installers
TrueConf is a video conferencing platform popular in Russian enterprise and government organisations as an on-premise alternative to Zoom or Microsoft Teams. According to Bleeping Computer, the hacktivist group Head Mare broke into unpatched TrueConf servers and replaced the software installer employees would download with a malicious version carrying a backdoor (a hidden program that gives attackers persistent, remote access to your system).
The attackers got in through TCP port 4307, which TrueConf leaves open by default and requires no login to access. From there, they used two internal flaws to escape the server's sandboxed environment (an isolated container designed to keep processes from affecting the wider system) and reach the underlying operating system with the highest possible privileges.
Once inside, they planted a web shell (a browser-accessible remote control panel hidden on the server) and swapped the legitimate TrueConf client installer for one bundled with the PhantomCore backdoor. Every employee who connected and downloaded what looked like a routine update was, in fact, installing malware. A second backdoor, PhantomGraph, ran hidden inside two files and received commands through a Microsoft OneDrive account — making its traffic harder to spot.
The flaws affect TrueConf Server versions 5.3.x, 5.4.x, and 5.5.x. Patches were released on June 18 in versions 5.3.9, 5.4.9, and 5.5.5. Kaspersky notes that even employees connecting to a partner organisation's compromised TrueConf server could pick up the infected installer.
What to do: If your organisation runs a TrueConf server, upgrade to version 5.3.9, 5.4.9, or 5.5.5 immediately. If you recently installed a TrueConf update, verify the installer's digital signature — the malicious versions are unsigned.
Sources

