Operation True Chaos is the name given to a 2026 intrusion campaign that exploited a TrueConf zero-day to compromise users through trojanized client updates. The activity was tentatively attributed to Chinese threat actors associated with use of the Havoc implant. In this campaign, attackers abused vulnerabilities in TrueConf infrastructure to deliver malicious software to downstream users via altered update mechanisms. Reported tradecraft indicates initial access through exploitation of public-facing software, followed by delivery of a backdoor implant for post-compromise control. The campaign is distinctively associated with trojanized software distribution and use of Havoc for command-and-control and post-exploitation. Attribution remains tentative rather than definitive.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separately referenced campaign involving exploitation of a TrueConf zero-day and trojanized client updates, mentioned as background/comparison rather than the main subject of this report.
A separately reported campaign targeting a TrueConf zero-day and compromising users via trojanized client updates; mentioned as background/comparison to the main Head Mare activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.