Tag: trojanize client installers

Hackers breach TrueConf to trojanize client installers with backdoors
News

Hackers breach TrueConf to trojanize client installers with backdoors

The hacktivist group Head Mare has been replacing client installers with malicious versions that deliver backdoors by taking advantage of flaws in unpatched TrueConf video conferencing servers. The attacker was able to launch the PhantomCore and PhantomGraph backdoors and run arbitrary code with the maximum level of privileges thanks to the exploited vulnerabilities. As a safe, on-premise substitute for Western technologies like Zoom and Microsoft Teams, TrueConf is a popular video conferencing application in Russia, particularly in the business and government sectors. The attack was found in July by researchers at the cybersecurity firm Kaspersky. They discovered that Head Mare hackers connected to the target TrueConf server without authentication by using TCP port 4307, which i...