Secretus logo

TrueConf Servers Hacked to Push Trojanized Installers

·8 min read

Compromised self-hosted TrueConf servers were turned into trusted malware distribution points after attackers replaced legitimate client installers with trojanized packages. Kaspersky links the activity to Head Mare, also tracked as PhantomCore, and reports affected servers at transportation, scientific and educational organizations.

This is a particularly dangerous supply-chain pattern because the download comes from the victim organization's own conferencing server. Users following an internal meeting workflow may see the expected hostname and product, while the server behind that trust has already been modified. Kaspersky says the malicious installers it observed did not carry a valid digital signature.

How the Head Mare chain worked

The activity had two related delivery paths. In the first, targets received links to supposed video meetings and were prompted to install conferencing software. The installation also deployed a previously unknown backdoor namedPhantomPxPigeon.

The second path removed the need for a lookalike download site. Attackers compromised TrueConf servers operated by real organizations and replaced the client distribution hosted there. Anyone downloading and running that package could be infected through a workflow that administrators and employees normally considered authoritative.

Kaspersky has not confirmed the initial server exploit. Its assessment is that the attackers likely used BDU:2025-10116, a TrueConf Server vulnerability patched by the vendor in August 2025. That is an attribution of the probable entry path, not proof that every compromised server was reached through the same bug.

Do not merge this with the separate TrueChaos zero-day

TrueConf also appeared in a different 2026 espionage campaign called TrueChaos. Check Point documented a Chinese-nexus actor exploitingCVE-2026-3502, a client update-integrity flaw affecting TrueConf client versions 8.1.0 through 8.5.2. A compromised on-premises server could present an arbitrary executable as an expected update, and clients trusted it without adequate validation. TrueConf fixed that issue in client version 8.5.3.

Head Mare and TrueChaos are separate clusters with different reported tooling and victimology. They belong in the same defensive analysis because both exploit the same architectural concentration of trust: control the self-hosted conference server, and the product's normal client-distribution path can multiply access across endpoints.

Why self-hosting did not contain the risk

On-premises collaboration can keep meetings and metadata out of a public SaaS tenant, but it also makes the organization responsible for the update server, package integrity, external exposure and incident telemetry. An internal hostname proves where a file came from; it does not prove the file remained authentic after the server was compromised.

The blast radius is asymmetric. One vulnerable server can expose every employee or managed endpoint that downloads its client. An attacker does not have to phish each user with an obviously foreign domain when administrators have already trained them to trust the organization's conferencing portal.

What TrueConf administrators should do now

  1. Update TrueConf Server. Confirm the running build is on a current, supported release containing the August 2025 server fixes and all later updates.
  2. Update the Windows client. Remove versions through 8.5.2 from managed endpoints and deploy a current release beyond 8.5.3.
  3. Verify every hosted installer. Check the publisher signature and compare package hashes with a known-good vendor source outside the TrueConf server.
  4. Quarantine unsigned packages. Kaspersky reports that the malicious distributions it found lacked a valid digital signature.
  5. Identify downloaders. Use proxy, web and server logs to enumerate endpoints that fetched a client installer during the suspected compromise window.
  6. Hunt those endpoints. Review installer execution, persistence, unusual child processes and outbound connections instead of assuming a clean antivirus scan proves the package was legitimate.
  7. Separate package publishing. Require signed releases, independent hash verification and a deployment pipeline that a conferencing-server compromise cannot rewrite silently.

Patch status is only half of the incident

If a server hosted a trojanized installer, updating TrueConf closes a suspected entry path but does not remediate clients that already ran the file. Treat the server and every downloading endpoint as separate forensic scopes. Preserve the malicious package safely, record its hash and signature state, and build a timeline from server modification through client execution and subsequent network activity.

The broader lesson resembles the recent Metabase incident: trusted internal tools become high-leverage attack infrastructure when one control plane serves many users or systems. Our Metabase zero-day analysiscovers the same need to patch, preserve evidence and then investigate everything downstream of the compromised platform.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus