TrueConf A.I CyberSecurity Scoring
TrueConf
Company Information
Website:https://trueconf.com
Employees number:105
Number of followers:5,000
NAICS:5112
Industry Type:Software Development
Homepage:trueconf.com
TrueConf Risk Score (AI oriented)
Between 700 and 749
TrueConfSoftware Development
Updated:
27/04/2026
27/04/2026
744/1000
Moderate
Ba
TrueConf Global Score (TPRM)
xxxx
TrueConfSoftware Development
Score locked

TrueConfModerate
Current Score
744Ba (MODERATE)
01000
3 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
745
JUNE 2026
745
MAY 2026
744
APRIL 2026
749
Vulnerability
01 Apr 2026 • TrueConf
TrueConf and Government entities in Southeast Asia: TrueConf Vulnerability Under Active Exploitation in Southeast Asia Government Attacks
Critical Zero-Day in TrueConf Video Conferencing Exploited in Targeted Espionage Campaign
744
CRITICAL-5
USATRU1775032190
Critical Zero-Day in TrueConf Video Conferencing Exploited in Targeted Espionage Campaign
Check Point Research uncovered a high-severity zero-day vulnerability (CVE-2026-3502, CVSS 7.8) in the TrueConf video conferencing client, actively exploited in a campaign dubbed Operation TrueChaos against government entities in Southeast Asia. The flaw stems from insufficient security checks in the application’s update mechanism, allowing attackers to distribute malicious payloads via the trusted update system.
TrueConf, widely used by government, military, and critical infrastructure sectors, operates on secure, on-premises networks. However, the vulnerability enables threat actors to compromise the central TrueConf server and replace legitimate updates with weaponized packages. When clients fetch the update, they unknowingly execute the malicious files, leading to system compromise.
In observed attacks, the threat actor gained access to a government IT department’s TrueConf server, infecting connected endpoints across multiple agencies. The attack chain involved DLL side-loading, network reconnaissance, and privilege escalation, culminating in the deployment of the Havoc post-exploitation framework. Key indicators include unsigned update files, the presence of poweriso.exe or 7z-x64.dll in the ProgramData folder, and unauthorized registry modifications.
Researchers attribute the campaign to a Chinese-nexus threat actor, citing tactics, infrastructure, and victim profiles consistent with known espionage operations. TrueConf has released version 8.5.3 to patch the vulnerability. Defenders are advised to monitor for compromise indicators, including the listed malicious files and command-and-control (C2) IP addresses.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2026
749
FEBRUARY 2026
749
JANUARY 2026
748
DECEMBER 2025
748
NOVEMBER 2025
748
OCTOBER 2025
748
SEPTEMBER 2025
752
Vulnerability
01 Sep 2025 • TrueConf
TrueConf: PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
PhantomCore Exploits TrueConf Vulnerabilities in Targeted Russian Cyberattacks
747
CRITICAL-5
TRU1777295519
PhantomCore Exploits TrueConf Vulnerabilities in Targeted Russian Cyberattacks
Since September 2025, the pro-Ukrainian hacktivist group PhantomCore (also known as Fairy Trickster, Head Mare, Rainbow Hyena, and UNG0901) has been actively targeting Russian organizations by exploiting critical vulnerabilities in TrueConf video conferencing software. According to a report by Positive Technologies, the group leveraged a chain of three unpatched flaws to execute remote commands on vulnerable servers, despite no public exploits being available at the time.
PhantomCore, active since 2022, is a politically and financially motivated threat actor known for data theft, network disruption, and ransomware deployment including variants based on leaked Babuk and LockBit source code. The group operates with high stealth, remaining undetected in victim networks for extended periods while continuously refining its offensive tools.
### Exploited Vulnerabilities
The attacks targeted three TrueConf Server vulnerabilities, all patched by the vendor on August 27, 2025, but first exploited in mid-September:
- BDU:2025-10114 (CVSS 7.5) – Insufficient access control allowing unauthenticated requests to administrative endpoints.
- BDU:2025-10115 (CVSS 7.5) – Arbitrary file read vulnerability.
- BDU-2025-10116 (CVSS 9.8) – Command injection flaw enabling arbitrary OS command execution.
Successful exploitation allowed attackers to bypass authentication, gain network access, and use compromised TrueConf servers as entry points for lateral movement. Positive Technologies observed the group deploying:
- A PHP-based web shell for file uploads and remote command execution.
- PhantomPxPigeon, a malicious TrueConf client with reverse shell capabilities.
- PhantomSscp, MacTunnelRat, and PhantomProxyLite for establishing persistent footholds via reverse SSH tunnels.
- ADRecon for reconnaissance and Veeam-Get-Creds for credential harvesting.
- DumpIt and MemProcFS for extracting sensitive data.
- WinRM, RDP, and Velociraptor for lateral movement and remote access.
- SOCKS proxies (microsocks, rsocx, tsocks) to control compromised hosts.
In some cases, attackers created a rogue admin account (TrueConf2) on breached servers.
### Broader Tactics and Recent Activity
PhantomCore has also used phishing lures including malicious ZIP/RAR archives to distribute backdoors capable of remote command execution and payload delivery. Recent campaigns in January–February 2026 targeted Russian organizations with these methods.
The group’s arsenal includes both publicly available tools (e.g., Velociraptor, MemProcFS) and custom malware (e.g., MacTunnelRAT, PhantomProxyLite). PhantomCore actively researches vulnerabilities in domestic Russian software to maximize infiltration across government and private-sector entities.
### Other Threat Groups Targeting Russia
PhantomCore is part of a growing wave of cyber threats against Russian infrastructure, including:
- CapFIX – A financially motivated group using ClickFix social engineering to deploy CapDoor (a backdoor for PowerShell/DLL execution) and off-the-shelf malware like AsyncRAT and SectopRAT. Recent campaigns masquerade as official government communications.
- Geo Likho – Focused on aviation and shipping sectors in Russia and Belarus since July 2024, delivering info-stealing malware. Accidental infections have been detected in Germany, Serbia, and Hong Kong.
- Mythic Likho – Uses phishing to deliver loaders (HuLoader, Merlin, ReflectPulse) leading to Loki, a Mythic-compatible backdoor. Linked to ExCobalt due to shared use of the Megatsune rootkit.
- Paper Werewolf (GOFFEE) – Distributes EchoGather trojan via Telegram under the guise of Starlink tools, alongside phishing pages for Telegram credential theft.
- Versatile Werewolf (HeartlessSoul) – Uses fake Star Debug and drone simulator websites to deploy Sliver and SoullessRAT, a trojan with command execution and screenshot capabilities.
- Eagle Werewolf – A newly identified group compromising drone-related Telegram channels to distribute AquilaRAT, a Rust-based trojan for file operations and command execution.
Despite overlapping goals and techniques, these groups operate independently with no evidence of direct coordination. Some, like Paper Werewolf, hijack Telegram accounts for future attacks, while Versatile Werewolf leverages generative AI to accelerate tool development.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
752
JANUARY 2024
752
Vulnerability
01 Jan 2024 • TrueConf
TrueConf and F5: Storm-1175 - Security Affairs
CISA Adds TrueConf Client Flaw to Known Exploited Vulnerabilities Catalog
749
CRITICAL-3
F5TRU1775587606
CISA Adds TrueConf Client Flaw to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in TrueConf Client to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation risks. The move underscores the urgency for organizations using the video conferencing software to apply patches or mitigations promptly.
In other recent cybersecurity developments:
- UAC-0255, a threat actor, impersonated Ukraine’s CERT-UA in phishing campaigns to distribute the AGEWHEEZE malware, targeting unsuspecting users.
- The pro-Iran Handala group breached Israeli defense contractor PSK Wind Technologies, highlighting ongoing geopolitical cyber threats.
- Storm-1175, a fast-moving threat group, deployed new exploits to infiltrate networks and deploy Medusa ransomware, demonstrating evolving attack techniques.
- Researchers uncovered GPUBreach, an exploit leveraging GPU memory bit-flips to achieve full system compromise, posing a novel risk to hardware-based security.
- Over 14,000 F5 BIG-IP APM instances remain exposed to a remote code execution (RCE) flaw, despite available patches, leaving organizations vulnerable to exploitation.
- The Qilin ransomware group claimed responsibility for hacking Germany’s Die Linke political party, adding to the growing trend of cyberattacks on political entities.
- North Korea-linked hackers stole $285 million from cryptocurrency platform Drift in a sophisticated attack, further fueling concerns over state-sponsored cybercrime.
- A major outage disrupted Russian banking apps and metro payment systems nationwide, though the cause whether cyberattack or technical failure remains unclear.
- A European Commission breach exposed data from 30 EU entities, with CERT-EU investigating the incident’s scope and impact.
- German authorities (BKA) identified two REvil ransomware operators linked to 130+ attacks in Germany, marking progress in dismantling the notorious group.
- An Italian spyware vendor created a fake WhatsApp app, targeting 200 users in a surveillance campaign.
- Fortinet patched CVE-2026-35616, a high-severity flaw actively exploited in the wild, urging immediate updates.
- Google addressed the fourth actively exploited Chrome zero-day of 2026, reinforcing the need for rapid browser security updates.
- North Korean hackers leveraged phishing LNK files and GitHub command-and-control (C2) infrastructure in new cyberattacks, showcasing persistent threat tactics.
These incidents reflect the escalating sophistication of cyber threats, from ransomware and espionage to supply chain and hardware-based attacks. Organizations are advised to monitor advisories and prioritize vulnerability remediation.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for TrueConf ??
What was TrueConf's A.I Rankiteo Cyber Score in June 2026 ??
What was TrueConf's A.I Rankiteo Cyber Score in May 2026 ??
What was TrueConf's A.I Rankiteo Cyber Score in April 2026 ??
What was TrueConf's A.I Rankiteo Cyber Score in March 2026 ??
What was TrueConf's A.I Rankiteo Cyber Score in February 2026 ??
What was TrueConf's A.I Rankiteo Cyber Score in January 2026 ??
What was TrueConf's A.I Rankiteo Cyber Score in December 2025 ??
What was TrueConf's A.I Rankiteo Cyber Score in November 2025 ??
What was TrueConf's A.I Rankiteo Cyber Score in October 2025 ??
What was TrueConf's A.I Rankiteo Cyber Score in September 2025 ??
What was TrueConf's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on TrueConf's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with TrueConf ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view TrueConf's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?