INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Government Networks
| 2026-04-27 11:54 LOW LOW DATA BREACH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks targeting servers running TrueConf video conferencing software in Russia since September 2025. The attackers, who are also known as Fairy Trickster, Head Mare, Rainbow Hyena, and UNG0901, have exploited three vulnerabilities - BDU:2025-10114 (CVSS score: 7.5), BDU:2025-10115 (CVSS score: 7.5), and BDU-2025-10116 (CVSS score: 9.8) - to breach Russian networks, with at least one successful compromise leading to the deployment of a PHP-based web shell that can upload files and execute remote commands. The attacks are believed to be part of PhantomCore's large-scale operations, which involve stealthy tactics such as continual updates and evolution of in-house offensive tools, allowing them to remain invisible in victim networks for extended periods.
Technical Mitigations AI-generated
• Patch TrueConf Server vulnerabilities BDU:2025-10114, BDU:2025-10115 and BDU-2025-10116 with the latest version available.
• Block or hunt for PhantomPxPigeon malicious TrueConf video conferencing client that implements a reverse shell to connect to a remote server.
• Use ADRecon for reconnaissance to detect potential vulnerabilities in breached environments.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
bi•••••.zone
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BabukBabukHavocHavoc
Target & Sectors
CIS
CIS
aviationaviation
governmentgovernment
manufacturingmanufacturing
Incident Timeline
July 2024
Threat actors using rogue drone simulator apps likely dropped SoullessRAT, a Windows trojan, on another website tied to the threat actor ("alphafly-drones[.]com") in July 2024.
Click on any entity below to view its context and source!
infrastructure
Windows
Another website tied to the threat actor ("alphafly-drones[.]com") has used rogue drone simulator apps to likely drop SoullessRAT, a Windows trojan that can run commands, upload files, capture screenshots, and execute binaries.
2026/04/27
PhantomCore, a pro-Ukrainian hacktivist group, has been attributed to attacks targeting servers running TrueConf video conferencing software in Russia since September 2025.
Click on any entity below to view its context and source!
infrastructure
7.5 Server vulnerabilities
The
TrueConf Server vulnerabilities
exploited in the attacks are listed below -
BDU:2025-10114
(CVSS score: 7.5) - An insufficient access control vulnerability that could allow an attacker to make requests to certain administrative endpoints…
infrastructure
Windows
…to recover passwords related to the Veeam Backup & Replication software
DumpIt and MemProcFS, for credential harvesting
Windows Remote Management (WinRM) and Remote Desktop Protocol (RDP), for lateral movement within the network perimeter
Vel…
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
…to recover passwords related to the Veeam Backup & Replication software
DumpIt and MemProcFS, for credential harvesting
Windows Remote Management (WinRM) and Remote Desktop Protocol (RDP), for lateral movement within the network perimeter
Vel…
Another website tied to the threat actor ("alphafly-drones[.]com") has used rogue drone simulator apps to likely drop SoullessRAT, a Windows trojan that can run commands, upload files, capture screenshots, and execute binaries.
Metrics
infrastructure
8
Server Vulnerabilities
The
TrueConf Server vulnerabilities
exploited in the attacks are listed below -
BDU:2025-10114
(CVSS score: 7.5) - An insufficient access control vulnerability that could allow an attacker to make requests to certain administrative endpoints…
Intelligence Sources
The Hacker News
2026-04-27
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:06
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
Breach Russian Networks
entity
9x
timeline
Temporal Reference
September 2025
date
6x
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
5x
tactic
Cyber Operation Type
Reconnaissance
tactic
4x
source region
Origin Country
Russian Federation
country
2x
target region
Target Country
Russian Federation
country
2x
malware
Malware Payload
Havoc
tool
2x
general metric
Cvss Score
10,116
cvss score
Contextual Telemetry
Context Block
4 METRICS
infrastructure
Affected Product
Windows
software
malware
Offensive Tool
Sliver
tool
infrastructure
Server Vulnerabilities
8
server vulnerabilities
general metric
Bdu:2025 Cvss Score
8
bdu:2025 cvss score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.