B
今週中
APTグループ「Head Mare」が、TrueConfビデオ会議サーバーの未修正の脆弱性を悪用して攻撃を行っていること
📌 一言でいうと
APTグループ「Head Mare」が、TrueConfビデオ会議サーバーの未修正の脆弱性を悪用して攻撃を行っていることが判明しました。攻撃者はサーバー上の正規クライアントインストーラーを感染済みのバージョンに置き換え、参加者にPhantomCoreおよびPhantomGraphマルウェアを配布させています。この攻撃チェーンにより、攻撃者は最高権限で任意のコードを実行することが可能です。
🔍該当判定
- 自社で「TrueConf」というビデオ会議サーバーを運用している
- TrueConfサーバーのアップデートを最新の状態にしていない
- 社内でTrueConfのクライアントソフトをインストールして利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
TrueConfサーバーの最新パッチを適用し、不審なファイルの置き換えや権限昇格の兆候がないかログを確認してください。また、公式ルート以外からのクライアントソフトのインストールを禁止してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】TrueConfサーバーの脆弱性を悪用したAPT攻撃への対応について
お疲れさまです。TrueConfサーバーを標的としたHead Mareグループによる攻撃に関する情報共有です。
■ 概要
TrueConfサーバーの脆弱性(KLCERT-26-057, KLCERT-26-058)を悪用し、正規のクライアントインストーラーをマルウェア(PhantomCore/PhantomGraph)に置き換える攻撃が観測されています。これにより、クライアントをインストールしたユーザーの端末で最高権限でのコード実行が行われるリスクがあります。
■ 影響範囲
- TrueConf ビデオ会議サーバー(未パッチバージョン)
■ 対応手順
1. TrueConfサーバーの最新アップデートを適用し、脆弱性を解消してください。
2. サーバー上のインストーラーファイルが改ざんされていないか、ハッシュ値等で確認してください。
3. ネットワーク境界でポート 4307/TCP への不審なアクセスがないか監視してください。
■ 参考情報
- Kaspersky Securelist レポート
対応優先度: 高
対応期限: 至急
お疲れさまです。TrueConfサーバーを標的としたHead Mareグループによる攻撃に関する情報共有です。
■ 概要
TrueConfサーバーの脆弱性(KLCERT-26-057, KLCERT-26-058)を悪用し、正規のクライアントインストーラーをマルウェア(PhantomCore/PhantomGraph)に置き換える攻撃が観測されています。これにより、クライアントをインストールしたユーザーの端末で最高権限でのコード実行が行われるリスクがあります。
■ 影響範囲
- TrueConf ビデオ会議サーバー(未パッチバージョン)
■ 対応手順
1. TrueConfサーバーの最新アップデートを適用し、脆弱性を解消してください。
2. サーバー上のインストーラーファイルが改ざんされていないか、ハッシュ値等で確認してください。
3. ネットワーク境界でポート 4307/TCP への不審なアクセスがないか監視してください。
■ 参考情報
- Kaspersky Securelist レポート
対応優先度: 高
対応期限: 至急
Subject: [Security Alert] APT Attack Targeting TrueConf Servers
Dear IT/Security Team,
We are sharing information regarding a campaign by the Head Mare APT group targeting TrueConf video conferencing servers.
■ Overview
Attackers are exploiting vulnerabilities (KLCERT-26-057, KLCERT-26-058) to replace legitimate TrueConf client installers with infected versions containing PhantomCore and PhantomGraph malware. This allows for arbitrary code execution with highest privileges on the end-user's system.
■ Scope
- Unpatched TrueConf Video Conferencing Servers
■ Mitigation Steps
1. Apply the latest security patches to the TrueConf server immediately.
2. Verify the integrity of client installer files on the server to ensure they have not been replaced.
3. Monitor for unauthorized traffic on port 4307/TCP.
■ Reference
- Kaspersky Securelist Report
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a campaign by the Head Mare APT group targeting TrueConf video conferencing servers.
■ Overview
Attackers are exploiting vulnerabilities (KLCERT-26-057, KLCERT-26-058) to replace legitimate TrueConf client installers with infected versions containing PhantomCore and PhantomGraph malware. This allows for arbitrary code execution with highest privileges on the end-user's system.
■ Scope
- Unpatched TrueConf Video Conferencing Servers
■ Mitigation Steps
1. Apply the latest security patches to the TrueConf server immediately.
2. Verify the integrity of client installer files on the server to ensure they have not been replaced.
3. Monitor for unauthorized traffic on port 4307/TCP.
■ Reference
- Kaspersky Securelist Report
Priority: High
Deadline: Immediate