logo

TrueConf Vulnerability Under Active Exploitation in Southeast Asia Government Attacks

ID: 0f40c9c9-1d7d-5ac1-a47b-f8936b5bc16c

STIX ID: report--0f40c9c9-1d7d-5ac1-a47b-f8936b5bc16c

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive Summary:** Check Point Research disclosed CVE-2026-3502, a high-severity flaw in the TrueConf client update mechanism exploited in Operation TrueChaos to deliver Havoc post-exploitation payloads; a compromised central TrueConf server pushed a malicious update that used DLL side-loading and privilege escalation to infect dozens of government endpoints, and researchers provided IOCs (malicious update filenames, DLL hashes, and C2 IPs) and recommended applying vendor patch 8.5.3 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.