Fake INPS SMS Uses AI to Screen Stolen Documents as Head Mare Exploits TrueConf Server Weaknesses + Video

Listen to this Post

Featured ImageA New Wave of Cyber Threats Targets Both Citizens and Enterprises

Cybersecurity threats are becoming increasingly deceptive. Criminals are no longer relying only on crude phishing pages, obvious malware, or poorly written scam messages. Modern campaigns are combining social engineering, convincing impersonation, cloud infrastructure, automated analysis, and artificial intelligence to make fraudulent operations harder to detect.

Two developments highlighted in the latest cybersecurity reporting demonstrate how broad this evolution has become. One campaign impersonates Italy’s National Institute for Social Security, known as INPS, using fraudulent SMS messages and a counterfeit website to trick victims into submitting sensitive documents and photographs. At the same time, the Head Mare threat actor has been linked to attacks against vulnerable TrueConf Server installations, where attackers obtained SYSTEM-level access and deployed multiple backdoors.

Although these operations target very different victims, they share a disturbing characteristic: trust is becoming the primary attack surface.

Fake INPS SMS Messages Turn Government Trust Into a Weapon

A smishing campaign impersonating INPS is targeting victims through fraudulent SMS messages designed to appear as legitimate communications from the Italian social-security institution.

The messages direct recipients toward a counterfeit portal that attempts to convince them that they need to provide personal documentation or photographs.

Instead of exploiting a sophisticated software vulnerability, the campaign exploits something much simpler and often much more effective: the victim’s confidence in an institution they recognize.

The Counterfeit Portal Is Built for Data Theft

Once a victim reaches the fraudulent website, the operation reportedly requests documents and photographs.

This makes the campaign considerably more dangerous than a conventional credential-phishing operation. Documents submitted to such portals can contain names, addresses, identification numbers, signatures, photographs, financial information, and other details that can potentially be reused in identity theft or additional fraud.

A single uploaded document can therefore provide criminals with far more information than a stolen password.

Artificial Intelligence Adds a New Layer to the Scam

One of the most notable elements of the campaign is the reported use of AI-based file checking.

The fraudulent portal reportedly analyzes uploaded files and uses automated checks to determine whether submitted content meets the attacker’s requirements.

This is an important development because it demonstrates how artificial intelligence can be incorporated into criminal workflows without necessarily generating sophisticated malware.

The AI component can effectively act as an automated quality-control system for stolen information.

Criminal Infrastructure Is Becoming More Automated

Traditional phishing operations often require attackers to manually review information collected from victims.

An automated file-processing system changes that model.

If a victim uploads an incorrect document, an incomplete photograph, or a file that does not satisfy the attacker’s requirements, automated validation can potentially identify the problem immediately.

This creates a more efficient criminal operation while reducing the amount of manual work required from attackers.

The Victim May Not Realize the Data Has Been Stolen

A major danger in document-focused phishing campaigns is that the victim may complete the process without immediately noticing anything unusual.

There may be no malware installation.

There may be no obvious account takeover.

There may be no dramatic error message.

Instead, the victim simply uploads the requested information and closes the browser.

The theft has already happened.

Why Government Impersonation Works So Well

Government institutions have a natural advantage in social-engineering attacks because people expect them to request personal information.

An SMS referencing social-security services, payments, benefits, identity verification, or administrative procedures can therefore create immediate urgency.

Attackers understand this psychological mechanism.

The objective is not necessarily to make the message perfect. It only needs to look legitimate long enough for the victim to act before questioning it.

The TrueConf Server Threat Shows the Other Side of the Problem

While the INPS campaign targets individuals through social engineering, the Head Mare operation demonstrates the continued danger posed by vulnerable enterprise infrastructure.

Kaspersky has reported that Head Mare abused unpatched TrueConf Server vulnerabilities to gain SYSTEM-level access.

TrueConf Server is enterprise communication software, meaning a successful compromise can potentially place an attacker inside an organization’s trusted infrastructure rather than merely stealing information from an individual user.

SYSTEM Access Changes the Entire Attack

Obtaining SYSTEM privileges on a Windows server represents a major escalation.

At that point, an attacker may have significantly greater control over the compromised machine, depending on its configuration and security controls.

The Head Mare activity reportedly involved deploying a web shell after obtaining access.

A web shell can provide attackers with persistent remote interaction with a compromised server and can become an important bridge between initial exploitation and broader intrusion activity.

PhantomCore and PhantomGraph Expand the Threat

The reported campaign also involved PhantomCore and PhantomGraph backdoors.

The presence of multiple malicious components suggests an operation designed for persistence, remote access, and continued control rather than a simple one-time intrusion.

The use of different payloads can also provide attackers with alternative mechanisms for maintaining access if one component is detected or removed.

OneDrive Can Become a Command-and-Control Channel

Another particularly interesting element is the reported use of OneDrive for command-and-control activity.

Cloud services are attractive to attackers because legitimate organizations already communicate with them every day.

Traffic involving a widely used cloud provider can therefore be less suspicious than communication with an unknown malicious server.

This does not make cloud infrastructure inherently dangerous. It demonstrates why security teams need to distinguish between legitimate cloud usage and malicious activity hidden inside trusted services.

Attackers Are Hiding Inside Normal Business Traffic

Modern attackers increasingly understand that obvious malicious infrastructure is easy to block.

A suspicious domain can be investigated.

A known malicious IP address can be blocked.

A strange executable can be quarantined.

But legitimate cloud services are much more difficult to prohibit because organizations depend on them.

This creates a dangerous security dilemma: blocking the service can disrupt the business, while allowing unrestricted access can provide attackers with additional opportunities.

Unpatched Servers Remain One of the Biggest Weaknesses

The TrueConf incident also reinforces a cybersecurity lesson that has existed for decades.

Patch management remains fundamental.

Organizations can deploy advanced endpoint detection, network monitoring, identity protection, and threat intelligence platforms, but an internet-facing server running vulnerable software can still provide attackers with the initial door they need.

Security is not only about detecting sophisticated attackers.

It is also about eliminating unnecessary opportunities for them.

The Common Thread Is Trust

The INPS smishing campaign abuses trust in a government institution.

The TrueConf attack abuses trust in enterprise software and legitimate infrastructure.

The technical methods are different, but the underlying objective is similar.

Attackers want defenders and victims to believe that something dangerous is ordinary.

That is increasingly becoming the defining characteristic of modern cybercrime.

Why These Two Incidents Matter Together

These incidents illustrate two different stages of cybersecurity evolution.

The first demonstrates how criminal groups are automating social engineering and data collection.

The second demonstrates how threat actors continue to exploit weaknesses in enterprise infrastructure to establish privileged access.

Together, they show that cybersecurity teams must protect both people and systems.

Focusing exclusively on malware is no longer enough.

Focusing exclusively on vulnerabilities is also insufficient.

The modern attack surface includes human behavior, cloud services, identity systems, web applications, messaging platforms, document workflows, and third-party infrastructure.

What Undercode Say:

The Human Layer Is Becoming Programmable

The INPS campaign demonstrates how social engineering is evolving beyond simple deception.

Attackers are increasingly constructing complete workflows around their victims.

The SMS is only the entry point.

The fraudulent portal is the collection mechanism.

The document-processing system becomes the validation layer.

AI can potentially automate the decision-making process.

This transforms phishing into something closer to a criminal service pipeline.

AI Can Increase Criminal Efficiency

The most concerning part is not necessarily that artificial intelligence is being used.

It is how easily automation can be incorporated into an existing attack.

An attacker does not need a futuristic autonomous hacking system.

A simple automated classifier can already reduce manual effort.

That can allow criminals to process more victims.

It can also help them identify valuable submissions.

The result is increased operational efficiency.

Identity Documents Are High-Value Targets

Passwords can be changed.

Identity documents are much harder to replace.

A stolen passport, identity card, photograph, or official document can potentially become useful for impersonation and fraud long after the original phishing campaign has disappeared.

This makes document theft particularly dangerous.

Organizations should therefore treat document uploads as sensitive transactions.

The TrueConf Incident Shows Why Internet-Facing Systems Matter

A vulnerable application exposed to the internet is effectively part of an organization’s external perimeter.

If attackers can exploit it, they may bypass many traditional defenses.

The initial compromise can then become a platform for persistence.

SYSTEM access makes the situation substantially more serious.

A web shell can provide additional remote control.

Backdoors can maintain persistence.

Cloud services can facilitate command-and-control communications.

Cloud Services Are Not Automatically Safe

Organizations sometimes create security assumptions around trusted cloud platforms.

Those assumptions can become dangerous.

An attacker using a legitimate cloud service does not make the activity legitimate.

Security teams need visibility into who is communicating with cloud services, which processes are responsible, what data is being transferred, and whether the behavior matches normal organizational activity.

Detection Must Become Behavioral

Blocking known indicators remains useful.

But indicators can change quickly.

Domains can disappear.

IP addresses can change.

Payload hashes can be modified.

Attackers can move their infrastructure.

Behavior is harder to replace.

Unexpected web-shell activity, unusual administrative actions, abnormal document uploads, suspicious cloud synchronization, and unexpected privileged processes can provide stronger detection opportunities.

Email and SMS Security Need the Same Attention

Many security programs still place greater emphasis on email phishing than SMS-based attacks.

That distinction is increasingly artificial.

Users communicate through multiple channels.

Attackers follow them.

Smishing campaigns can be just as persuasive as email phishing, particularly when they impersonate institutions that routinely communicate through mobile messaging.

Organizations should educate users about fraudulent links regardless of the communication channel.

Security Awareness Needs to Become More Practical

Telling users to “be careful” is not enough.

People need concrete warning signs.

Unexpected requests for identity documents should trigger suspicion.

Urgent messages containing unfamiliar links should be verified independently.

Government services should be accessed through known official websites rather than links supplied in unsolicited messages.

Employees should know how to report suspicious activity quickly.

Patch Management Is Still a Strategic Control

The TrueConf case is another reminder that vulnerability management cannot be treated as a background IT task.

Internet-facing applications should receive particular attention.

Organizations need an accurate inventory.

They need to know which systems are exposed.

They need to prioritize actively exploited vulnerabilities.

They need emergency patching procedures.

And they need compensating controls when immediate patching is impossible.

Privileged Access Magnifies Damage

SYSTEM-level compromise is dangerous because attackers gain a much stronger position inside the operating system.

Security teams should minimize unnecessary privileges.

Administrative accounts should be protected with strong authentication.

Privileged operations should be monitored.

Servers should be segmented.

And critical infrastructure should not automatically trust every internal connection.

Web Shell Detection Deserves Special Attention

A web shell can hide inside an otherwise legitimate web server environment.

Defenders should monitor unexpected script creation and modification.

They should investigate suspicious child processes launched by web applications.

They should monitor unusual outbound connections from web servers.

They should also compare application directories against known-good baselines.

Persistence Should Be Assumed After High-Privilege Exploitation

When attackers obtain privileged access, simply removing the initial vulnerability is not necessarily enough.

The organization should investigate whether additional accounts were created.

It should examine scheduled tasks.

It should inspect services and startup mechanisms.

It should review web directories.

It should search for suspicious binaries and scripts.

It should analyze outbound network activity.

The goal is to determine whether the attacker left behind additional access mechanisms.

One Incident Can Become a Larger Breach

Initial compromise is often only the beginning.

Attackers may move laterally.

They may search for credentials.

They may identify file servers.

They may target backup infrastructure.

They may compromise additional endpoints.

They may steal sensitive information before deploying additional malware.

This is why incident response must investigate the entire attack chain rather than focusing only on the original vulnerable application.

Security Teams Need Cross-Domain Visibility

The two campaigns demonstrate why cybersecurity cannot operate in isolated silos.

Threat intelligence teams need visibility into emerging campaigns.

SOC analysts need endpoint telemetry.

Identity teams need authentication data.

Network teams need traffic visibility.

Application teams need vulnerability intelligence.

Users need practical security guidance.

The strongest defense connects these pieces.

The Attack Surface Is Becoming More Human and More Automated

That contradiction is important.

Attackers are using automation while simultaneously exploiting human psychology.

Machines process the data.

Humans provide it.

Machines maintain access.

Humans create trust.

Machines move information.

Humans click the link.

Cybersecurity defenses therefore need to protect both sides of the equation.

Trust Should Be Verified, Not Assumed

The safest response to an unexpected request is independent verification.

Do not use the link inside a suspicious message.

Open the official website manually.

Contact the institution through a known communication channel.

For businesses, verify unusual requests through established internal procedures.

Trust should be earned by the communication itself, not granted because a logo looks familiar.

The Next Generation of Phishing Will Be More Interactive

Static phishing pages are becoming less impressive.

Future campaigns are likely to become increasingly responsive.

Pages may adapt to user behavior.

Forms may validate submitted information.

Automated systems may determine whether a victim is valuable.

AI may help criminals personalize messages and process collected information.

This creates an environment where phishing increasingly resembles a legitimate digital service.

Defenders Need Automation Too

The answer is not to abandon automation.

It is to use automation defensively.

Security teams can automatically flag suspicious domains.

They can detect unusual file uploads.

They can correlate authentication anomalies.

They can monitor cloud-service behavior.

They can quarantine suspicious endpoints.

They can automate vulnerability prioritization.

The race between attackers and defenders is increasingly becoming a race between automation systems.

Security Culture Remains the Final Defense

Technology can reduce risk.

It cannot eliminate human judgment.

Employees and citizens still need to recognize suspicious requests.

They need easy reporting mechanisms.

They need confidence that reporting mistakes will not automatically result in punishment.

A strong security culture turns users from passive targets into active sensors.

The Bigger Lesson

The most important lesson from these incidents is simple.

Cybersecurity is no longer about defending a fixed perimeter.

The perimeter moves with the user.

It moves with the cloud.

It moves with the application.

It moves with the smartphone.

It moves with every document upload.

It moves with every third-party service.

Organizations that understand this shift will be better positioned to detect attacks before they become major breaches.

Deep Analysis

Inspecting Active Network Connections

Security teams investigating a potentially compromised Linux host can begin by examining active connections:

ss -tulpn

Unexpected listening services should be investigated, especially on systems that are supposed to expose only a limited number of applications.

Searching for Suspicious Processes

Administrators can inspect running processes with:

ps aux --sort=-%cpu

Unexpected interpreters, scripts, or processes launched by web-service accounts deserve additional investigation.

Reviewing Recently Modified Files

A quick search for recently modified files can help identify suspicious changes:

find /var/www -type f -mtime -2 -ls

For a TrueConf or other web-server investigation, analysts should adapt the directory to the application’s actual installation path.

Checking Outbound Connections

Unexpected outbound connections from an application server can provide valuable evidence:

ss -tunap

Security teams should correlate unfamiliar destinations with process ownership and known organizational traffic patterns.

Reviewing Authentication Activity

Linux administrators can review recent logins with:

last

Failed authentication attempts can also be examined through system logs, depending on the distribution:

journalctl --since "24 hours ago" | grep -i "failed"

Searching for Persistence Mechanisms

Security teams should inspect scheduled tasks:

crontab -l

They should also review system-wide cron locations:

ls -la /etc/cron.d/

Additional persistence mechanisms may include services, startup scripts, SSH keys, user accounts, and application-level configuration.

Monitoring File Integrity

Organizations can establish known-good application baselines and compare them against current files.

For example:

sha256sum /path/to/suspicious/file

Hash comparison alone is not sufficient for a complete investigation, but it can help analysts identify unexpected changes.

Windows Servers Require Equivalent Visibility

Because the reported TrueConf exploitation involves Windows SYSTEM-level access, defenders should also inspect Windows processes, services, scheduled tasks, event logs, PowerShell activity, and network connections.

Useful defensive checks include:

Get-Process
Get-Service
Get-ScheduledTask
Get-NetTCPConnection

These commands should be used as part of an authorized incident-response process rather than as a substitute for comprehensive forensic analysis.

Protecting Against Smishing

Users should avoid opening links in unexpected government or financial messages.

Instead, navigate directly to the

Organizations can reinforce this behavior through mobile security awareness programs.

Mobile-device management and DNS filtering can also provide additional protection where appropriate.

Protecting Sensitive Documents

Organizations should minimize unnecessary document collection.

If identity documents are required, upload systems should use strong authentication, encrypted connections, access controls, logging, retention limits, and anomaly detection.

Users should be informed why a document is required and where it will be stored.

Defending Internet-Facing Applications

Organizations should maintain an inventory of externally exposed applications.

They should continuously monitor vulnerability advisories affecting those applications.

Critical patches should be prioritized based on exposure, exploitability, business impact, and evidence of active exploitation.

Segmenting Critical Servers

A compromised communication server should not automatically provide access to critical internal systems.

Network segmentation can restrict lateral movement.

Application servers should have only the network access they actually require.

Protecting Cloud-Based Communications

Organizations should monitor unusual use of cloud storage and synchronization services.

Security teams should correlate cloud activity with endpoint processes, user identities, timestamps, and network behavior.

Legitimate cloud services can still become part of a malicious attack chain.

Incident Response Should Follow the Entire Chain

When an intrusion is discovered, defenders should investigate:

Initial access → Exploitation → Privilege escalation → Persistence → Command and control → Discovery → Credential access → Lateral movement → Data theft → Impact

Stopping at the first stage can leave an attacker hidden elsewhere in the environment.

Government Impersonation Campaign

✅ The supplied report describes an INPS-themed smishing campaign using a fraudulent portal to collect documents and photographs.

AI-Based File Processing

✅ The report specifically identifies automated or AI-based checking of uploaded files as part of the fraudulent workflow.

Head Mare and TrueConf

✅ The supplied reporting states that Head Mare exploited unpatched TrueConf Server vulnerabilities, obtained SYSTEM-level access, deployed a web shell, and used PhantomCore and PhantomGraph-related backdoors.

Prediction

(+1) AI-Assisted Fraud Will Become More Automated

Criminal phishing infrastructure will increasingly use automation to validate stolen documents and classify victims.

Smishing campaigns will become more convincing as attackers improve message personalization.

Fraudulent portals may dynamically change their behavior based on the information submitted by victims.

Security platforms will increasingly use behavioral analytics and AI to detect these attacks.

(-1) Traditional Trust Signals Will Become Less Reliable

Logos, official-looking websites, government names, and familiar cloud services will no longer provide reliable evidence that a communication is legitimate.

Organizations that rely exclusively on reputation-based security controls will face increasing difficulty detecting abuse of legitimate platforms.

Users who respond to urgency without independently verifying requests will remain highly exposed.

Final Takeaway

The INPS smishing campaign and the Head Mare attacks against TrueConf Server represent different forms of cybercrime, but they point toward the same uncomfortable reality.

Attackers are learning how to make malicious activity look normal.

A fraudulent website can imitate a trusted institution.

An automated system can process stolen documents.

A compromised server can run legitimate-looking web infrastructure.

A familiar cloud service can become part of command-and-control activity.

The strongest defense is therefore not a single security product. It is layered verification.

Patch exposed systems quickly.

Monitor privileged activity.

Inspect suspicious cloud behavior.

Protect sensitive documents.

Train users to distrust unexpected requests.

And most importantly, investigate the entire attack chain whenever something unusual appears.

The cybersecurity battle is moving deeper into the places people and organizations naturally trust. The organizations that recognize that shift early will have a far better chance of stopping the next attack before trust becomes the attacker’s greatest weapon.

▶️ Related Video (76% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube