2026-08-23HIGHexploitedBoth flaws are now catalogued as exploited; the reach extends to organisations that run no TrueConf server of their own
Head Mare
actor · actor:head-mare
Espionage cluster tracked by Kaspersky against Russian organisations; Kaspersky reclassified it from hacktivist to APT in its 2026-08-11 report, citing TTP sophistication and the absence of destructive activity. Observed since at least July 2026 chaining CVE-2026-72529 and CVE-2026-72530 against unpatched TrueConf Server instances to plant a web shell and replace the server's distributed Windows client installer with a trojanised copy carrying PhantomCore (Kaspersky ICS CERT / Securelist, 2026-08-11/12).
Coverage
1
first 2026-08-23 → last 2026-08-23
Latest activity
2026-08-23
Both flaws are now catalogued as exploited; the reach extends to organisations that run no TrueConf server of…
Peak priority
high
1 high
Targets
energy
sectors: energy, transport, telco · regions: europe
Sources cited
5
4 hosts
Action items (2)
Do-now tasks recorded on the entries about Head Mare, newest first. Check the date before acting on an older one.
- Patch TrueConf Server to 5.3.9, 5.4.9 or 5.5.5 and take port 4307/TCP off any internet-facing interface, it listens by default, and Kaspersky's own testing found the flaw present in every release since 2022, so an unpatched older build is affected even though it falls outside the published CVE ranges.2026-08-23CVE-2026-72529 +1
- Treat any TrueConf server that hosted external or contractor participants before patching as compromised until cleared: check whether the distributed Windows client installer under ClientInstFiles still carries a valid vendor signature, and check the web-accessible script directory for a modified locale.php.2026-08-23CVE-2026-72529 +1
Defender insights
What each entry about Head Mare tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
- PhantomCoredelivered inside the trojanised TrueConf client installer
- PhantomGraphbackup command-and-control channel on compromised TrueConf servers via a stolen OneDrive account
- PhantomHook*nix rootkit listening for commands smuggled inside the TrueConf protocol
- PhantomReact*nix backdoor using GitHub as its command-and-control channel
Story timeline
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (11 across 6 tactics)
11 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell · Create or Modify System Process: Systemd Service · Create or Modify System Process: Windows Service · Compromise Host Software Binary
- Privilege EscalationCreate or Modify System Process: Systemd Service · Create or Modify System Process: Windows Service · Escape to Host
- StealthObfuscated Files or Information · Masquerading: Match Legitimate Resource Name or Location
- Credential AccessOS Credential Dumping: LSASS Memory
- Command and ControlWeb Service: Bidirectional Communication · Protocol Tunneling
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
T1554Compromise Host Software Binary×1
Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries. Common software binaries are SSH clients, FTP clients, email clients, web browsers, and many other user or server applications.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
Privilege Escalation TA0004
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
T1611Escape to Host×1
Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
Credential Access TA0006
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
Command and Control TA0011
T1102.002Web Service: Bidirectional Communication×1
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-08-23/trueconf-server-kev-head-mare-trojanized-installer · ATT&CK page ↗
Entries about Head Mare (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- PhantomCore×1
- PhantomGraph×1
- PhantomHook×1
- PhantomReact×1
- TrueConf Server×1
- TrueConf Server missing authentication for a critical function on port 4307/TCP; an unauthenticated caller invokes an undocumented function to run a script inside the server's isolated environment. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20; chained with CVE-2026-72530 by Head Mare to reach SYSTEM. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5.×1
- TrueConf Server sandbox escape, a flaw in the isolated environment's code-generation logic lets an attacker who already has script execution there run arbitrary OS commands as NT AUTHORITY\SYSTEM. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5.×1
Where this entity is cited
Source distribution
- ics-cert.kaspersky.com2 (40%)
- cisa.gov1 (20%)
- securelist.com1 (20%)
- trueconf.com1 (20%)
All cited sources (5)
- cisa.govCISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- ics-cert.kaspersky.comKaspersky ICS CERThttps://ics-cert.kaspersky.com/publications/reports/2026/08/12/head-mare-exploits-vulnerabilities-in-trueconf-server-to-deliver-phantomcore-malware/
- ics-cert.kaspersky.comKaspersky ICS CERT (KLCERT-26-057)https://ics-cert.kaspersky.com/vulnerabilities/trueconf-server-missing-authentication-for-critical-function/
- securelist.comKaspersky Securelisthttps://securelist.com/head-mare-targets-trueconf-server-with-phantomcore/120988/
- trueconf.comTrueConfhttps://trueconf.com/blog/news/security-fixes-updates-and-advisories