A zero-day flaw in the TrueConf Windows client, tracked as CVE-2026-3502 and rated CVSS 7.8, was exploited in the wild to compromise government entities in Southeast Asia. Researchers said the vulnerability stemmed from missing integrity and authenticity checks in TrueConf’s update validation process, allowing anyone who controlled an on-premises TrueConf server to replace legitimate client updates with arbitrary executables delivered through the trusted update channel.
In the campaign dubbed TrueChaos, attackers used a weaponized TrueConf update to install malware while still performing a legitimate software upgrade, then dropped files including poweriso.exe and a malicious 7z-x64.dll for DLL sideloading. The intrusion reportedly involved persistence, privilege escalation, reconnaissance, hands-on-keyboard activity, and retrieval of additional payloads, with researchers assessing that the operation likely aimed to deploy the Havoc command-and-control framework and was linked with moderate confidence to a Chinese-nexus threat actor. TrueConf released a fix in Windows client version 8.5.3.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-3502, a TrueConf Client vulnerability involving download of code without an integrity check, to its Known Exploited Vulnerabilities Catalog after determining there was evidence of active exploitation. The agency said federal civilian agencies must remediate the flaw under Binding Operational Directive 22-01 and urged all organizations to prioritize patching.
Check Point Research disclosed the zero-day vulnerability CVE-2026-3502, detailed its exploitation in the TrueChaos campaign, and assessed with moderate confidence that the activity is linked to a Chinese-nexus threat actor. The disclosure also described the attack chain involving a malicious TrueConf update, DLL sideloading, and follow-on hands-on-keyboard activity.
After responsible disclosure, TrueConf developed a fix for the update validation vulnerability tracked as CVE-2026-3502. The patch was included in TrueConf Windows client version 8.5.3 released in March 2026.
Check Point observed in-the-wild exploitation of the TrueConf Windows client flaw beginning in early 2026, targeting government entities in Southeast Asia. Attackers abused control of on-premises TrueConf servers to distribute weaponized updates, leading to malware deployment, persistence, and likely Havoc implant delivery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcecisa.gov
Open sourcehelpnetsecurity.com
Open sourcegithub.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.