PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

Reported 11 Aug 2026 by otx · Severity: medium

The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and