Code Defence Cyber security

Hackers breach TrueConf video conferencing servers to trojanize client installers with backdoors

Active software supply chain intrusions targeting on-premises video conferencing infrastructure have been detailed, where hacktivist groups exploited unauthenticated server flaws to replace legitimate client installers with malicious payloads.

The attack campaign targets on-premises TrueConf video conferencing servers via default open TCP port 4307. Threat actors associated with the Head Mare group leveraged an unauthenticated code execution vulnerability paired with a sandbox escape flaw to gain system administrative privileges on target host servers. Once elevated access was secured, the actors modified internal web scripts to replace legitimate client installation binaries with trojanized versions that deploy PhantomCore and PhantomGraph backdoors onto connecting user endpoints.

Subverting an internal communication server to distribute trojanized installers creates severe supply chain exposure across enterprise networks. Because employees trust internal software distribution channels, downloading trojanized updates grants threat actors unmonitored persistence across internal workstations, enabling credential theft, audio interception, and lateral network pivoting.

– Apply current security hotfixes published by TrueConf to close unauthenticated port 4307 access vectors.

– Inspect video conferencing web server paths for modified PHP scripts or unverified web shell deployments.

– Verify binary hashes of client installers hosted on internal portals against official vendor reference signatures.

– Monitor host endpoints for unexpected background process creations originating from video conferencing software updates.

Enterprise collaboration platform resilience relies on continuous installer file integrity monitoring combined with strict service isolation to ensure internal distribution servers cannot be subverted into malware deployment channels. #CodeDefence #TrueConf #SupplyChain #Backdoor #Kaspersky #EndpointSecurity #AppSec
/

Scroll to Top