Check Point Research has discovered a critical zero-day vulnerability in the TrueConf video conferencing client.
Tracked as CVE-2026-3502 with a CVSS score of 7.8, this flaw is currently being exploited in targeted attacks against government entities in Southeast Asia.
Dubbed “Operation TrueChaos,” the campaign uses the application’s trusted update system to deliver the Havoc post-exploitation payload to vulnerable machines.
The Vulnerability: CVE-2026-3502
TrueConf is a popular video conferencing platform used globally, especially by government, military, and critical infrastructure sectors that require secure, on-premises networks.
The software is designed to operate entirely within a private local network without internet access, ensuring strict data privacy.
However, researchers from CheckPoint found a major flaw in how the TrueConf client handles updates. When the application starts, it checks the on-premises server for a newer version.
If an update is available, the client downloads and installs it. The vulnerability exists because this update process lacks proper security checks for authenticity and file integrity.

An attacker controlling the central TrueConf server can replace the legitimate update with a malicious program.
The connected clients will then blindly trust and execute this malicious file as if it were a normal update.
The TrueChaos Attack Chain
In the observed attacks, a threat actor compromised a government IT department’s central TrueConf server.
This server was connected to dozens of government agencies. By swapping the legitimate update with a weaponized package, the attacker infected all connected endpoints simultaneously without needing to compromise them individually.
The update upgraded the client normally but dropped two hidden files: a benign executable named poweriso.exe and a malicious file called 7z-x64.dll.
As per your preference for clear points without tables, the attack chain unfolded as follows:
- The system loaded the malicious DLL file using a technique called DLL side-loading.
- The attacker ran reconnaissance commands to map the network and check running processes.
- Additional tools were downloaded from a remote server, including a file named iscsiexe.dll.
- The attacker bypassed Windows security prompts to gain elevated system privileges.
- Finally, the system connected to an attacker-controlled server to download the Havoc payload, an open-source post-exploitation framework often abused by hackers.
Based on the tactics, techniques, and the choice of cloud hosting providers, researchers assess with moderate confidence that a Chinese-nexus threat actor is behind Operation TrueChaos.
The targeted region and the victim profile align with known espionage campaigns.
TrueConf has released version 8.5.3 to fix this issue. To identify potential compromises, defenders should hunt for unsigned update files, the unexpected presence of poweriso.exe or 7z-x64.dll in the ProgramData folder, and unauthorized registry run keys. Organizations must apply the vendor patch immediately to secure their networks.
Indicators of Compromise
trueconf_windows_update.exe – Malicious TrueConf client update
22e32bcf113326e366ac480b077067cf
iscsiexe.dll – Loader
9b435ad985b733b64a6d5f39080f4ae0
7z-x64.dll – Havoc implant
248a4d7d4c48478dcbeade8f7dba80b3
43.134.90[.]60 – Havoc C2
43.134.52[.]221 – Havoc C2
47.237.15[.]197 – Havoc C2
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





