← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

Head Mare case makes conferencing-client provenance an incident question

Kaspersky’s investigation describes compromised TrueConf infrastructure serving altered client installers associated with PhantomCore and PhantomGraph.

Source published 2026-08-11Incident responseResearch briefing
Original publication preview: Head Mare case makes conferencing-client provenance an incident question
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky’s investigation describes compromised TrueConf infrastructure serving altered client installers associated with PhantomCore and PhantomGraph. The report ties endpoint findings to an unpatched conferencing server investigated after July activity.

Why it matters

Validate the origin of software distributed by internal services as well as public vendors. Preserve deployment records, installer hashes and server logs so that affected endpoints can be scoped from evidence.

Scope and limits

This is an account of a particular campaign and affected software versions. Consult the current vendor advisory for remediation; the presence of TrueConf alone is not a compromise indicator.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-08-11. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC