Tuesday, September 15, 2026

TrueConf Vulnerability Under Active Exploitation in Southeast Asia Government Attacks

Check Point Research has discovered a critical zero-day vulnerability in the TrueConf video conferencing client.

Tracked as CVE-2026-3502 with a CVSS score of 7.8, this flaw is currently being exploited in targeted attacks against government entities in Southeast Asia.

Dubbed “Operation TrueChaos,” the campaign uses the application’s trusted update system to deliver the Havoc post-exploitation payload to vulnerable machines.

The Vulnerability: CVE-2026-3502

TrueConf is a popular video conferencing platform used globally, especially by government, military, and critical infrastructure sectors that require secure, on-premises networks.

The software is designed to operate entirely within a private local network without internet access, ensuring strict data privacy.

However, researchers from CheckPoint found a major flaw in how the TrueConf client handles updates. When the application starts, it checks the on-premises server for a newer version.

If an update is available, the client downloads and installs it. The vulnerability exists because this update process lacks proper security checks for authenticity and file integrity.

Malicious Client Update Attack Chain (Source: checkpoint)
Malicious Client Update Attack Chain (Source: checkpoint)

An attacker controlling the central TrueConf server can replace the legitimate update with a malicious program.

The connected clients will then blindly trust and execute this malicious file as if it were a normal update.

The TrueChaos Attack Chain

In the observed attacks, a threat actor compromised a government IT department’s central TrueConf server.

This server was connected to dozens of government agencies. By swapping the legitimate update with a weaponized package, the attacker infected all connected endpoints simultaneously without needing to compromise them individually.

The update upgraded the client normally but dropped two hidden files: a benign executable named poweriso.exe and a malicious file called 7z-x64.dll.

As per your preference for clear points without tables, the attack chain unfolded as follows:

  • The system loaded the malicious DLL file using a technique called DLL side-loading.
  • The attacker ran reconnaissance commands to map the network and check running processes.
  • Additional tools were downloaded from a remote server, including a file named iscsiexe.dll.
  • The attacker bypassed Windows security prompts to gain elevated system privileges.
  • Finally, the system connected to an attacker-controlled server to download the Havoc payload, an open-source post-exploitation framework often abused by hackers.

Based on the tactics, techniques, and the choice of cloud hosting providers, researchers assess with moderate confidence that a Chinese-nexus threat actor is behind Operation TrueChaos.

The targeted region and the victim profile align with known espionage campaigns.

TrueConf has released version 8.5.3 to fix this issue. To identify potential compromises, defenders should hunt for unsigned update files, the unexpected presence of poweriso.exe or 7z-x64.dll in the ProgramData folder, and unauthorized registry run keys. Organizations must apply the vendor patch immediately to secure their networks.

Indicators of Compromise

trueconf_windows_update.exe – Malicious TrueConf client update
22e32bcf113326e366ac480b077067cf

iscsiexe.dll – Loader
9b435ad985b733b64a6d5f39080f4ae0

7z-x64.dll – Havoc implant
248a4d7d4c48478dcbeade8f7dba80b3

43.134.90[.]60 – Havoc C2
43.134.52[.]221 – Havoc C2
47.237.15[.]197 – Havoc C2

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News