Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

2026-08-11T20:51:46Z4a3017bf9a0c34a1cd0caeec54a245d22665e000f6f98c7faf7e042a443b19e0
APTAiTM phishingAnatsaC2DNS tunnelingESXiGenieLockerGoogle Apps ScriptHead MareKerberoastingMFA bypassOctLurkPhantomCorePhantomGraphProject CAV3RNSilkLurkToy Ghouls/Mallox? no explicit attribution beyond Toy Ghouls; doTrueConfcloud platformscredential dumpingcyber-espionageexploitationkeyloggingmemory-resident malwareransomware

What happened

Kaspersky Securelist threat intelligence covering active APT campaigns, malware families, ransomware, phishing infrastructure, cloud-based MFA bypasses, DNS tunneling, and regional cyber-espionage activity. Notable items include Head Mare exploiting an unpatched TrueConf server to deploy PhantomCore and PhantomGraph, Project CAV3RN using Google Apps Script and DNS-based C2, OctLurk and SilkLurk backdoors targeting Central Asia, GenieLocker ransomware affecting Windows/Linux/ESXi, and Mirage Kitten tools targeting the Middle East and Africa.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
4a3017bf9a0c34a1cd0caeec54a245d22665e000f6f98c7faf7e042a443b19e0
Enrichment time
2026-08-11T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.