None
EN
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
['The Hacker News', 'Ravie Lakshmanan', 'Aug']
The Hacker News
The activity involves exploiting a vulnerability chain in the TrueConf videoconferencing server to replace the original TrueConf client installers with poisoned versions that deliver the PhantomCore backdoor and remote access trojan (RAT) into susceptible systems.
The attack impacts TrueConf server versions 5.3.x up to 5.3.9, 5.4.x up to 5.4.9, 5.5.x up to 5.5.5, and earlier.
The attack chain is as follows -Attackers connect to the TrueConf server on TCP port 4307, which is open by default.
The attackers replace the file "...\public\js\locale.php" with a web shell to facilitate persistent remote access to the compromised server.
The vulnerabilities have since been patched by the vendor in the latest TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026.