A serious security vulnerability in TrueConf has been used as a zero-dayas part of a campaign targeting government agencies in Southeast Asia. The malicious operation is being tracked under the name TrueChaos.

The vulnerability, known as CVE-2026-3502 (CVSS score: 7.8), concerns a lack of integrity checking when retrieving the application update code, allowing an attacker to distribute a malicious update, resulting in arbitrary code execution. The vulnerability has been fixed in the TrueConf Windows client, starting with version 8.5.3, released earlier this month.
See also: F5 BIG-IP APM: Critical RCE vulnerability used in attacks
TrueConf: How exactly does the vulnerability work?
The issue arises from the abuse of TrueConf's update validation mechanism , allowing an attacker, controlling the on-premises TrueConf server, to distribute and execute arbitrary files on all connected endpoints. An attacker who manages to gain control of the local TrueConf server can replace the update package with a malicious version, which is then retrieved by the client application installed on the clients' endpoints (due to insufficient validation, which should ensure that the update provided by the server has not been tampered with).

The TrueChaos campaign is exploiting this vulnerability in the update mechanism to potentially deploy an open-source command-and-control (C2) framework called Havoc. The activity has been attributed, with moderate certainty, to Chinese hackers.
Attacks exploiting the vulnerability were first documented by Check Point in early 2026. The likely end goal is the use of a malicious installer that leverages DLL side-loading to launch a DLL backdoor.
See also: Vertex AI vulnerability exposes Google Cloud data and files
The DLL implant (“7z-x64.dll”) has also been observed performing hands-on-keyboard actions to conduct reconnaissance, establish persistence , and retrieve additional payloads (“iscsiexe.dll”) from an FTP server (“47.237.15[.]197”). The main goal of “iscsiexe.dll” is to ensure the execution of an innocent binary (“poweriso.exe”) that is installed to load the backdoor.
Although the exact final stage malware is unclear, it is estimated that the ultimate goal is the development of the Havoc implant.

Possible use of Havoc and connection to China
TrueChaos’ connections to a Chinese threat actor are based on observed tactics such as DLL side-loading, Alibaba Cloud, and Tencent for C2 infrastructure. The same victim was also targeted during the same period by ShadowPad, a sophisticated backdoor widely used by Chinese groups.
The use of Havoc has also been attributed to a Chinese threat actor calledAmaranth-Dragon. It was used in attacks targeting government and police agencies across Southeast Asia in 2025.
See also: Fortinet Forticlient EMS: Critical vulnerability used in attacks
Exploiting CVE-2026-3502 did not require the attacker to compromise each endpoint individually. Instead, the attacker exploited the trust relationship between a central local TrueConf server and its clients. By replacing a legitimate update with a malicious one, they turned the product's normal update flow into a malware distribution channel across multiple connected government networks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
