PhantomCore Exploits TrueConf Flaws in Russian Servers

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- PhantomCore has been targeting Russian TrueConf video‑conferencing servers since September 2025, according to Positive Technologies.
- TrueConf released patches for three critical vulnerabilities (BDU:2025‑10114, BDU:2025‑10115, BDU‑2025‑10116) on 27 August 2025, but the first attacks were detected mid‑September 2025.
- BDU:2025‑10114 together with BDU:2025‑10115 and BDU‑2025‑10116 formed an exploit chain that bypassed authentication, read arbitrary files, and executed OS commands on the servers.
- PhantomPxPigeon was deployed as a malicious TrueConf client that implements a reverse shell, enabling remote command execution and traffic proxying.
- PhantomSscp and related tools such as MacTunnelRat and PhantomProxyLite were used to establish reverse SSH tunnels, create a rogue admin user “TrueConf2”, and maintain footholds within the breached network.
- PhantomCore used ZIP/RAR‑based phishing emails in January‑February 2026 to deliver a backdoor that could run remote commands and drop additional payloads on Russian hosts.
Why it matters: Russian organizations using TrueConf lose network integrity and face credential theft, while PhantomCore gains access to sensitive data and can further disrupt government and private sectors; the attacks show the group’s ability to weaponize zero‑day exploits despite vendor patches, raising the threat level for Russian IT infrastructure.
Ask SkimNews



