Head Mare hackers trojanize TrueConf installers via server exploits
Hacktivist group exploits unpatched video conferencing servers to distribute backdoored client software, compromising downstream users who install legitimate-looking updates.
The Head Mare hacktivist group has compromised TrueConf video conferencing servers by exploiting unpatched vulnerabilities, replacing legitimate client installers with trojanized versions that deliver backdoors to end users. The attack targets the supply chain: users downloading what appear to be official TrueConf clients from compromised servers receive malware instead.
TrueConf is a video conferencing platform used primarily in Russia and former Soviet states, with deployments in government, enterprise, and healthcare. The breach method relies on server-side vulnerabilities that allow attackers to modify hosted files. Once a server is compromised, every subsequent download of the client installer becomes a vector for malware distribution.
The trojanized installers function normally while silently deploying backdoors, making detection difficult for users who trust the source. BleepingComputer reports the campaign has been active but did not specify the number of affected servers or the scope of downstream infections. TrueConf has not issued a public advisory on patching timelines or mitigation steps.
- 01Organizations using TrueConf face supply-chain risk if downloading clients from compromised servers.
- 02IT teams must verify installer integrity via cryptographic hashes before deployment.
- 03Unpatched TrueConf servers remain exploitable; vendors must issue and enforce patches urgently.
- 04Backdoor infections may persist undetected, enabling espionage or lateral movement within networks.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.