Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
2026-08-11T20:51:46Z•4a3017bf9a0c34a1cd0caeec54a245d22665e000f6f98c7faf7e042a443b19e0
APTAiTM phishingAnatsaC2DNS tunnelingESXiGenieLockerGoogle Apps ScriptHead MareKerberoastingMFA bypassOctLurkPhantomCorePhantomGraphProject CAV3RNSilkLurkToy Ghouls/Mallox? no explicit attribution beyond Toy Ghouls; doTrueConfcloud platformscredential dumpingcyber-espionageexploitationkeyloggingmemory-resident malwareransomware
What happened
Kaspersky Securelist threat intelligence covering active APT campaigns, malware families, ransomware, phishing infrastructure, cloud-based MFA bypasses, DNS tunneling, and regional cyber-espionage activity. Notable items include Head Mare exploiting an unpatched TrueConf server to deploy PhantomCore and PhantomGraph, Project CAV3RN using Google Apps Script and DNS-based C2, OctLurk and SilkLurk backdoors targeting Central Asia, GenieLocker ransomware affecting Windows/Linux/ESXi, and Mirage Kitten tools targeting the Middle East and Africa.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 4a3017bf9a0c34a1cd0caeec54a245d22665e000f6f98c7faf7e042a443b19e0
- Enrichment time
- 2026-08-11T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.