📅 Source : Kaspersky Securelist (https://securelist.ru), publié le 7 août 2026, mis à jour le 10 août 2026.

🎯 Contexte général En juillet 2026, les experts de Kaspersky ont découvert une nouvelle campagne du groupe APT Head Mare exploitant une chaîne de deux vulnérabilités inédites dans TrueConf Server (logiciel de vidéoconférence) pour compromettre des organisations russes dans les secteurs de l’instrumentation, de l’électronique, du transport, de l’énergie et de l’IT.

🔓 Vecteur d’attaque et vulnérabilités Les attaquants ont exploité deux vulnérabilités enchaînées (identifiants internes KLCERT-26-057 et KLCERT-26-058) permettant l’exécution de code arbitraire avec les privilèges maximaux :

  • KLCERT-26-057 : connexion sans authentification sur le port 4307/TCP (ouvert par défaut), permettant l’envoi et l’exécution d’un script malveillant sur le serveur.
  • KLCERT-26-058 : échappement de l’environnement isolé (sandbox escape), permettant l’exécution de commandes dans le contexte de l’OS.
  • Les versions affectées : TrueConf Server 5.3.x < 5.3.9, 5.4.x < 5.4.9, 5.5.x < 5.5.5 et versions antérieures.
  • Les correctifs ont été publiés le 18 juin 2026.

🪲 Chaîne d’infection

  1. Connexion non authentifiée au port 4307/TCP
  2. Injection et exécution d’un script malveillant
  3. Sandbox escape via KLCERT-26-058
  4. Exécution de code en tant que NT AUTHORITY\SYSTEM
  5. Remplacement du fichier ...\public\js\locale.php par un webshell PHP
  6. Via le webshell : collecte d’informations, accès privilégié à la base de données TrueConf, substitution de l’installateur TrueConf Client par une version infectée contenant PhantomCore

🦠 Malwares déployés

  • PhantomCore : backdoor intégré dans l’installateur TrueConf Client falsifié ; persistance via clé de registre COM hijacking (HKCU\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32).
  • PhantomGraph : backdoor en deux modules :
    • SysExcSvc.dll : réception des commandes C2 via Microsoft OneDrive
    • SysReadSvc.dll : exécution des commandes et sauvegarde des résultats
    • Persistance via services Windows installés par commande PowerShell encodée en Base64

🕵️ Actions post-compromission observées

  • Dump mémoire du processus lsass.exe
  • Reconnaissance (hostname, whoami)
  • Navigation vers C:\Windows\System32\inetsrv
  • Lancement d’un tunnel SSH inverse
  • Exécution de commandes via fichiers BATCH temporaires (%TEMP%\cmd_cmd_*.bat)

🏭 Secteurs ciblés Instrumentation, électronique, transport, énergie, IT et développement logiciel — organisations russes.

📄 Type d’article Analyse technique et rapport d’incident produit par Kaspersky ICS CERT, incluant des indicateurs de compromission détaillés, des règles YARA, des règles SIEM (KUMA) et des détections EDR (KEDR Expert, MDR).

🧠 TTPs et IOCs détectés

Acteurs de menace

TTP

  • T1190 — Exploit Public-Facing Application (Initial Access)
  • T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
  • T1059.003 — Command and Scripting Interpreter: Windows Command Shell (Execution)
  • T1505.003 — Server Software Component: Web Shell (Persistence)
  • T1574.002 — Hijack Execution Flow: DLL Side-Loading (Persistence)
  • T1547.009 — Boot or Logon Autostart Execution: Shortcut Modification (Persistence)
  • T1543.003 — Create or Modify System Process: Windows Service (Persistence)
  • T1546.015 — Event Triggered Execution: Component Object Model Hijacking (Privilege Escalation)
  • T1068 — Exploitation for Privilege Escalation (Privilege Escalation)
  • T1562.002 — Impair Defenses: Disable Windows Event Logging (Defense Evasion)
  • T1027 — Obfuscated Files or Information (Defense Evasion)
  • T1003.001 — OS Credential Dumping: LSASS Memory (Credential Access)
  • T1082 — System Information Discovery (Discovery)
  • T1033 — System Owner/User Discovery (Discovery)
  • T1102.002 — Web Service: Bidirectional Communication (Command and Control)
  • T1572 — Protocol Tunneling (Command and Control)
  • T1195.002 — Supply Chain Compromise: Compromise Software Supply Chain (Initial Access)
  • T1566 — Phishing (Initial Access)

IOC

  • IPv4 : 81.177.32.12AbuseIPDB · VT · ThreatFox
  • IPv4 : 194.87.239.71AbuseIPDB · VT · ThreatFox
  • IPv4 : 194.87.93.153AbuseIPDB · VT · ThreatFox
  • IPv4 : 38.244.205.244AbuseIPDB · VT · ThreatFox
  • IPv4 : 31.59.102.61AbuseIPDB · VT · ThreatFox
  • Domaines : penzadogshelter.siteVT · URLhaus · ThreatFox
  • Domaines : trendy-market.siteVT · URLhaus · ThreatFox
  • Domaines : bright-deals.siteVT · URLhaus · ThreatFox
  • Domaines : nova-stream.siteVT · URLhaus · ThreatFox
  • Domaines : rinomobile.inkVT · URLhaus · ThreatFox
  • Domaines : urbanpixel.storeVT · URLhaus · ThreatFox
  • Domaines : flexish.shopVT · URLhaus · ThreatFox
  • Domaines : media-hub.todayVT · URLhaus · ThreatFox
  • Domaines : cosmetic-deals.storeVT · URLhaus · ThreatFox
  • Domaines : vks.gossopka.forumVT · URLhaus · ThreatFox
  • MD5 : 4d27b4eb1c5dbb3d8160f29b8119523eVT · MalwareBazaar
  • MD5 : 748c9f8cb1065000616204935f96207fVT · MalwareBazaar
  • MD5 : c5a460e4e68a088f6e51b2c6474642ecVT · MalwareBazaar
  • MD5 : 129462164a7d52e9ea8560b60f0412c5VT · MalwareBazaar
  • MD5 : ec0bf4a2186a88874e9f26f07cfeb532VT · MalwareBazaar
  • MD5 : b348642146ea34771e5785c5857950f5VT · MalwareBazaar
  • MD5 : c915cb6c2aeb863ee8479238e1644217VT · MalwareBazaar
  • MD5 : 0e79996d9483d1e44fea32b0a48c2c19VT · MalwareBazaar
  • MD5 : 2bb75c20e778eb5c416965bd4d4259b1VT · MalwareBazaar
  • MD5 : b3a6fee3307f1c26841fd5c603e2b013VT · MalwareBazaar
  • MD5 : 8fcc3e4ccbf1725d9989fb464abf3561VT · MalwareBazaar
  • MD5 : 489f43be558b2679284ceabed7adc4f3VT · MalwareBazaar
  • MD5 : dd1fd2b459b97b7d59375cb8383cd19aVT · MalwareBazaar
  • MD5 : 0e4541c3153ec5ed01497f19cf4f63d0VT · MalwareBazaar
  • MD5 : 12d4e8f5295f2ef7e0f9bfc0f4830939VT · MalwareBazaar
  • MD5 : 7f267006cac10f341c356b62fe493527VT · MalwareBazaar
  • MD5 : ee2861d5965e8730708cd1da8a93fa4cVT · MalwareBazaar
  • MD5 : c3a2abe8756910f42582b04a44ea3514VT · MalwareBazaar
  • MD5 : 43f435c3c437bc879a2d7d4634f43494VT · MalwareBazaar
  • MD5 : aee9642b45b099cb7f3053b9b680b425VT · MalwareBazaar
  • Fichiers : locale.php
  • Fichiers : trueconf_windows_update.exe
  • Fichiers : doc.txt
  • Fichiers : usocacheddata.txt
  • Fichiers : sysexcsvc.dll
  • Fichiers : sysreadsvc.dll
  • Fichiers : SysExcSvc.dll
  • Fichiers : SysReadSvc.dll
  • Fichiers : graphi-refresh.dat
  • Fichiers : api-ms-win-crt-time-l1-1-0-2.dll
  • Fichiers : schedul2-bin
  • Fichiers : omicluster
  • Fichiers : libzvbi-tchain.so.2
  • Fichiers : cx2
  • Chemins : C:\Windows\System32\inetsrv\SysExcSvc.dll
  • Chemins : C:\Windows\System32\inetsrv\SysReadSvc.dll
  • Chemins : C:\Windows\System32\inetsrv\graphi-refresh.dat
  • Chemins : C:\Windows\System32\inetsrv\share\input_*.txt
  • Chemins : C:\Windows\System32\inetsrv\share\output_*.txt
  • Chemins : %TEMP%\cmd_cmd_*.bat
  • Chemins : %LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll
  • Chemins : /etc/systemd/system/omicluster.service
  • Chemins : /etc/systemd/system/schedul2-bin.service
  • Chemins : /opt/acronis/bin/schedul2-bin
  • Chemins : /omi/bin/omicluster
  • Chemins : /usr/lib64/libzvbi-tchain.so.2
  • Chemins : /var/tmp/cx2

⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 10 août 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • PhantomCore (backdoor)
  • PhantomGraph (backdoor)
  • WebShell (locale.php) (other)

🟢 Indice de vérification factuelle : 75/100 (haute)

  • ⬜ securelist.ru — source non référencée (0pts)
  • ✅ 15000 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 62 IOCs dont des hashes (15pts)
  • ✅ 5/6 IOCs confirmés (AbuseIPDB, ThreatFox, URLhaus, VirusTotal) (15pts)
  • ✅ 18 TTPs MITRE identifiées (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ✅ acteur(s) identifié(s) : Head Mare (5pts)
  • ⬜ pas de CVE à vérifier (0pts)

IOCs confirmés externellement :

  • 194.87.239.71 (ip) → VT (4/91 détections)
  • 194.87.93.153 (ip) → VT (3/91 détections)
  • penzadogshelter.site (domain) → VT (4/91 détections)
  • trendy-market.site (domain) → VT (5/91 détections)
  • bright-deals.site (domain) → VT (4/91 détections)

🔗 Source originale : https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/