INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Government Networks

| 2026-04-27 11:54 LOW LOW DATA BREACH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks targeting servers running TrueConf video conferencing software in Russia since September 2025. The attackers, who are also known as Fairy Trickster, Head Mare, Rainbow Hyena, and UNG0901, have exploited three vulnerabilities - BDU:2025-10114 (CVSS score: 7.5), BDU:2025-10115 (CVSS score: 7.5), and BDU-2025-10116 (CVSS score: 9.8) - to breach Russian networks, with at least one successful compromise leading to the deployment of a PHP-based web shell that can upload files and execute remote commands. The attacks are believed to be part of PhantomCore's large-scale operations, which involve stealthy tactics such as continual updates and evolution of in-house offensive tools, allowing them to remain invisible in victim networks for extended periods.
Technical Mitigations AI-generated
• Patch TrueConf Server vulnerabilities BDU:2025-10114, BDU:2025-10115 and BDU-2025-10116 with the latest version available. • Block or hunt for PhantomPxPigeon malicious TrueConf video conferencing client that implements a reverse shell to connect to a remote server. • Use ADRecon for reconnaissance to detect potential vulnerabilities in breached environments.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

bi•••••.zone
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BabukBabukHavocHavoc
Target & Sectors
CIS CIS aviationaviation governmentgovernment manufacturingmanufacturing
Incident Timeline
‎July 2024
Threat actors using rogue drone simulator apps likely dropped SoullessRAT, a Windows trojan, on another website tied to the threat actor ("alphafly-drones[.]com") in July 2024.
infrastructure Windows
‎2026/04/27
PhantomCore, a pro-Ukrainian hacktivist group, has been attributed to attacks targeting servers running TrueConf video conferencing software in Russia since September 2025.
infrastructure 7.5 Server vulnerabilities
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
8
Server Vulnerabilities
Intelligence Sources