PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
Reported 11 Aug 2026 by otx · Severity: medium
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and