Head Mare threat actors exploit unpatched TrueConf servers to inject malicious code into client installers. Kaspersky detected the campaign in July 2026 targeting Russian organizations across critical sectors including energy, transport, electronics, and IT.

The attackers leverage a vulnerability chain in TrueConf, a Russian video conferencing platform, to replace legitimate client installers with PhantomCore malware. This approach enables supply chain compromise at scale. Victims download what appears to be authentic TrueConf software but receive backdoored versions instead.

Head Mare has repeatedly exploited TrueConf vulnerabilities in prior campaigns, indicating the threat group maintains active knowledge of the platform's flaws and relies on delayed patching by target organizations. The sectors targeted, particularly energy and transport infrastructure, suggest strategic intent to establish persistent access in critical national industries.

The attack chain works by compromising unpatched TrueConf servers, then modifying the installer distribution mechanism. When users download the client software through compromised servers, they receive PhantomCore instead of legitimate software. PhantomCore functions as a backdoor, granting attackers remote code execution and long-term persistence.

Organizations face risk on multiple fronts. Unpatched TrueConf deployments create direct server compromise risk. Employees downloading installers from compromised servers inadvertently execute malware. Supply chain trust erodes when legitimate software distribution channels become weaponized.

The timing and targeting pattern indicates this campaign prioritizes infrastructure access. Head Mare's focus on Russian industry sectors, particularly energy and transport, aligns with patterns associated with state-sponsored espionage groups, though Kaspersky did not explicitly attribute the activity to government actors.

Organizations running TrueConf must immediately patch all instances to the latest versions. Security teams should audit systems for PhantomCore indicators of compromise and