Build1 distinct publisher2 min readUpdated
Kaspersky ICS CERT says Head Mare chains CVE-2026-72529 and CVE-2026-72530 to swap the official Windows client installer for a PhantomCore build. Both bugs are now in CISA's KEV catalog.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
The chain is a sandboxed script execution bug bolted to a sandbox escape, and the second half is what makes the first half worth anything. According to Kaspersky ICS CERT, an attacker who can reach port 4307/TCP uses CVE-2026-72529 to execute scripts inside an isolated environment [3], then CVE-2026-72530 to leave that environment and run code on the host [4]. What the host holds is the point. One part of it is the web root, where `locale.php` is replaced with a web shell used to survey the infrastructure and reach the TrueConf database with privileged access [5]. The other is the client distribution directory, where the official Windows x64 installer is replaced with a build carrying PhantomCore [6].
The fix is published across three maintained release branches, 5.3.9, 5.4.9 and 5.5.5 [13][16]. That spread says the exposure is not limited to whatever version shipped most recently, so an operator sitting on an older supported line does not get to treat this as someone else's upgrade problem.
Detection is where the design gets awkward. The tampered update installs the official client alongside the PhantomCore DLL, and it presents as a normal TrueConf client update [7], so an endpoint team looking for an unfamiliar process finds a legitimate one running exactly as expected. The malware hooks TrueConf network functions to hide files and takes commands over the TrueConf protocol itself, while a second backdoor uses GitHub as its C2 [9][10]. Egress rules keyed on unusual destinations will not fire on either. What is left is file-level: modifications to `locale.php`, deleted event logs and a hash change on `ClientInstFiles/trueconf_windows_client_x64.exe` on the server [5][11][6], plus `api-ms-win-crt-time-l1-1-0-2.dll` under `%LOCALAPPDATA%\TrueConf\Client` and the services `SysExcSvc` or `SysReadSvc` on participant machines [8][11].
Kaspersky publishes a four-rung confirmation ladder for this intrusion, from crafted requests to 4307/TCP with no tampering, through script execution via the first CVE, through host code execution and web shell after the second, to tampered installers running on participant devices [14]. Three of those four rungs are visible on hardware the server owner controls. The fourth is only visible on endpoints owned by everyone who joined a call [15]. That asymmetry is the whole story: patching to a fixed build closes the server, and closes nothing on the machines that already pulled the update.
Kaspersky also notes that no email vector is required [12]. The delivery mechanism is the vendor's own update path, so gateway filtering, attachment policy and user training sit outside the blast radius entirely. The mitigations on offer are the unglamorous ones: patch, restrict 4307/TCP to trusted networks, and watch the integrity of the web root and the distribution files [13].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Kaspersky ICS CERT published a report titled "Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participants", dated 2026-08-12 and updated 2026-08-21, with severity rated critical.
CVE-2026-72529 and CVE-2026-72530 were assigned and added to the CISA Known Exploited Vulnerabilities catalog, which significantly increased their priority as actively exploited vulnerabilities.
The attacker reaches port 4307/TCP and uses CVE-2026-72529 to execute scripts inside an isolated environment.
The attacker uses CVE-2026-72530 to escape the isolated environment and execute code on the host.
The attacker replaces locale.php (TrueConf Server public/js/locale.php) with a web shell to investigate the infrastructure and gain privileged access to the TrueConf database; modifications to locale.php are listed as an indicator.
The attacker replaces the official Windows x64 client installer with one containing PhantomCore; hash changes in ClientInstFiles/trueconf_windows_client_x64.exe are listed as an indicator.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-sourced
The technical substance is unusually specific for a one-source cluster: named CVEs, a port, exact file paths and hashes-of-interest, service names, C2 behaviour and a four-tier confirmation model. It is nonetheless one dev.to relay of one vendor report, with KEV listing as the only external corroboration referenced and no vendor advisory or second research team in the cluster.
Confirmed exploitation, unknown scale
Real-world exploitation is established: an investigated intrusion plus KEV listing for both CVEs, and remediated builds exist on three branches. What is absent is any measure of breadth — no victim counts, no exposed-server telemetry, no patch-uptake figures — so exploitation is proven but its footprint is not.
Broadly aligned, slightly ahead of scope data
The framing stays close to what is evidenced: the post grades confirmation tiers, flags that only requests to port 4307/TCP may indicate an unsuccessful attempt, and confines itself to IOCs and mitigations. The mild positive gap comes from a critical severity label and a supply-chain-to-participants narrative carried by one investigated case, with no exposure or victim-scale data to size the risk.
Vendor threat-research incentive, no commercial pitch in text
The underlying research comes from a security vendor's ICS CERT unit, which has a standing interest in visible, severe threat findings and in detection coverage. Offsetting that, the relayed text sells nothing, names no product to buy, references CISA KEV as an outside check and points remediation at the affected vendor's own patched builds.
Moderate
High internal coherence and unusually specific, checkable indicators support the mechanism claims, but a single publisher relaying a single vendor report, absent vendor advisory confirmation and absent any scope measurement, caps confidence in the story's breadth and in the attribution.
security
CISA puts TrueConf Server in the exploited bucket, and port 4307/TCP does not care about your LAN1 distinct publisher
build
AI-written code fails the same four ways, and every gate you own reports green1 distinct publisher
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
security
Akrites switches on in September with 20-odd members and a one-to-10 engineer donation band1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 21, 2026