Hackers weaponize TrueConf flaw to implant backdoors via fake installers

Russian-speaking hacktivists known as Head Mare have been actively weaponizing an unpatched vulnerability in TrueConf video conferencing servers to push malicious Windows installers to unsuspecting users. The campaign replaces legitimate client software with trojanized versions that drop Cobalt Strike beacons and other backdoors, according to security researchers monitoring the activity.
Head Mare’s operation follows the recent disclosure of CVE-2024-42169, a path traversal flaw in TrueConf’s internal update mechanism that allows unauthenticated attackers to overwrite files on the server. By injecting a malicious MSI installer into the update channel, the group ensures that any Windows user who updates their TrueConf client receives the backdoored package instead of the legitimate software. The poisoned installers maintain the original digital signature, making them harder to detect.
A widening attack surface
TrueConf is widely used by government agencies, enterprises, and educational institutions across Russia and the CIS for secure video conferencing. The trojanized installers have been observed targeting both internal and external users, indicating that the breach is not limited to a single organization. Security teams are urged to verify the integrity of TrueConf client installers through checksums or direct downloads from the vendor’s official site before deployment.
Why it matters
This incident illustrates how a single unpatched server-side vulnerability can cascade into a supply-chain compromise, affecting thousands of downstream users. It also highlights the growing trend of hacktivist groups pivoting from data leaks to live sabotage, leveraging trusted software channels to deliver persistent backdoors. Organizations running TrueConf should prioritize patching and implement rigorous software verification processes to prevent similar attacks.
Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

