
The Head Mare hacker group breached an unpatched TrueConf server. They replaced the original installer with a malicious fake version. When employees clicked to perform a routine update, they were infected immediately.
Key points to know:
• Hackers gained access through an open TCP port 4307 without requiring a password
• PhantomCore and PhantomGraph malware stole account credentials from victims’ computers
• The fake installer lacked a digital signature
• TrueConf has released patch versions 5.3.9, 5.4.9, and 5.5.5 since June 18
[Insight: Updates coming from a company’s internal server can also carry malware. Always verify the digital signature before installing any software.]
Kun Long
Author at The Sharing KH