Skip to main content

Signal in the noise.

Kaspersky Warns: "Phantom Meeting" Cyberattacks Escalate, Threatening Global Digital Supply Chains

Kaspersky has uncovered a new wave of sophisticated cyberattacks, dubbed "phantom meetings," that trick users into downloading malicious software. These attacks, led by a group called "Head Mare," install a dangerous backdoor named PhantomPxPigeon, giving attackers almost full control over infected systems and posing a significant threat to digital supply chains globally.

1 min read
Kaspersky Warns: "Phantom Meeting" Cyberattacks Escalate, Threatening Global Digital Supply Chains

Kaspersky has issued a warning about a growing campaign of advanced cyberattacks led by a group known as "Head Mare." These attacks target educational institutions, scientific organizations, and entities in the energy sector by exploiting video conferencing applications. This clearly shows the increasing risks tied to our growing reliance on digital work tools. The company explained that the campaign, first spotted in February 2026 with activity traced back to December 2025, uses a sophisticated social engineering method. It starts with sending fake links for video meeting invitations. When a victim interacts, they are prompted to download what looks like legitimate communication software, but it actually contains malicious code that plants a backdoor into their system. Kaspersky has named this backdoor "PhantomPxPigeon." It gives attackers almost complete control over infected devices, allowing them to steal data and execute commands remotely without the user knowing. In a significant development, the company also revealed a new wave of attacks targeting TrueConf software servers within several organizations. Official installation files were replaced with malicious versions, opening the door to even more dangerous scenarios involving digital supply chain breaches, especially since users often rely on seemingly trusted internal download sources. Although these attacks were first detected in Russia, cybersecurity experts warn that they could spread globally. This is because they are reusable and easy to deploy across remote work environments, which have become a key part of both government and private sector organizations. This escalation shows a significant shift in attack strategies. Breaches are no longer just about directly targeting systems; instead, they focus on using everyday work tools as entry points. This means organizations must re-evaluate their digital security policies, especially in regions like the Middle East and Africa, which are seeing rapid expansion in digital transformation.

Related editorial