TrueConf and ViPNet Flaws Exploited to Target Russian Firms

TrueConf and ViPNet Flaws Exploited to Target Russian Firms

The rapid evolution of modern cyber warfare has transformed standard corporate tools into primary vectors for high-stakes industrial espionage, as seen in the recent targeting of critical Russian infrastructure. Threat actors have successfully demonstrated that even specialized communication and security software are not immune to deep exploitation when unpatched vulnerabilities remain exposed to the public internet. This specific campaign highlights the vulnerability of established videoconferencing systems and encrypted update channels, which are typically trusted by large-scale enterprises for their internal operations. By weaponizing these platforms, attackers gain a foothold that bypasses traditional perimeter defenses, allowing for the silent exfiltration of sensitive data and the long-term monitoring of corporate activities. The convergence of these two distinct attack paths—one targeting collaboration software and the other hijacking a secure update mechanism—represents a significant escalation in technical precision and strategic planning by advanced persistent threat groups.

1. The Methodology of the TrueConf Server Intrusion

The threat group known as Head Mare has initiated a complex series of operations targeting various Russian industrial and information technology firms by weaponizing unpatched instances of TrueConf software. This specific attack sequence begins with the establishment of a connection to the TrueConf server through TCP port 4307, which serves as a common entry point that remains open for standard communication functions in many corporate networks. Once a connection is established, the attackers utilize the vulnerability identified as KLCERT-26-057 to execute a malicious script within the environment. Although this script initially runs in a restricted and sandboxed space, the threat actors quickly escalate their access by leveraging a second vulnerability, KLCERT-26-058. This secondary exploit allows them to bypass the sandbox limitations and run commands directly on the host system with full administrative permissions, often operating under the NT AUTHORITY\SYSTEM account to ensure complete control over the server.

After achieving administrative control, the attackers maintain persistent access by replacing the legitimate locale.php file with a custom web shell that provides a backdoor into the compromised system. This access is utilized to perform extensive data collection, where the threat group gathers detailed network information and accesses the internal TrueConf database to extract sensitive user information. A primary objective of this stage involves replacing the original client installers on the server with versions that contain the PhantomCore Trojan, ensuring that every user who downloads the software becomes infected. Furthermore, the group deploys the PhantomGraph backdoor, a sophisticated two-part malware that utilizes Microsoft OneDrive for its command-and-control operations. This backdoor consists of two specific components: SysExcSvc.dll for data exfiltration and SysReadSvc.dll for executing received instructions. Persistence is then solidified by registering these DLLs as Windows services using encoded PowerShell scripts.

2. Hijacking the Security Update Infrastructure of ViPNet

In a parallel development of significant concern, a separate campaign likely orchestrated by a Chinese-speaking threat actor has been observed hijacking the update mechanism of the ViPNet product suite. The core of this intrusion involves the HelloInjector logic, which is designed to identify and infiltrate active processes on a target machine without alerting security monitors. The malware first checks the name of the process it is currently running in to determine if it has already reached its destination. If it is not running as svchost.exe, it searches the system for an active svchost process that specifically includes the netsvcs string within its command path. Upon locating the appropriate host, the injector uses specific memory-writing functions to insert its malicious code directly into the identified process. This technique effectively hides the malware’s activity within a legitimate system service, making detection extremely difficult for standard antivirus solutions.

Once the initial injection is successful, the primary payload, known as HelloProxy, becomes active and functions as a hidden proxy to facilitate further movement within the network. This proxy is responsible for loading several specialized sub-modules that expand the attacker’s capabilities, including the HelloExecutor and HelloCleaner tools. HelloExecutor is primarily used for running arbitrary system commands and establishing secure SSH tunnels that allow the threat actor to bypass firewalls and maintain a stable connection to the infected environment. In contrast, HelloCleaner is a dedicated tool used for scrubbing system logs and removing the digital evidence of the intrusion, thereby ensuring that the group can operate for extended periods without being detected by security audits. Additionally, the attackers utilize HelloBackdoor, a program written in the Rust language, which is used for the efficient transfer of files between the infected system and the remote command server.

3. Strategic Remediation and Future Defense Protocols

The historical context of these threat actors reveals a pattern of high-level technical capability and a specific focus on regional targets within the industrial and government sectors. Head Mare, for instance, has a documented history of utilizing zero-day exploits against Russian targets and various government entities throughout Southeast Asia. The manufacturer of TrueConf responded to these particular threats by releasing comprehensive security patches in June 2026, specifically targeting versions 5.3.9, 5.4.9, and 5.5.5 to mitigate the vulnerabilities exploited by the group. Regarding the ViPNet campaign, researchers have linked the activity to a Chinese-speaking group with low confidence, primarily due to the presence of specific software mirrors and web references found within the code. These links suggest a shared infrastructure or knowledge base common among regional threat actors, although the precise attribution remains subject to further analysis of the evolving malware samples.

The emergence of these coordinated attacks demonstrated the critical need for a more proactive approach to securing internal communication tools and software update channels. Organizations were forced to realize that traditional security models, which often prioritized external firewalls over internal application security, were no longer sufficient against modern adversaries. To address these systemic risks, security teams implemented rigorous patch management schedules that prioritized the immediate deployment of manufacturer updates for all videoconferencing and security platforms. Furthermore, the adoption of zero-trust architectures became a priority, ensuring that even internal processes were subject to constant verification and monitoring. By shifting toward an identity-centric security model and enhancing the visibility of encrypted network traffic, firms sought to reduce the dwell time of sophisticated malware like PhantomCore and HelloNet. These actions established a stronger baseline for future resilience, though the threat landscape continued to evolve rapidly.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address