logo

TrueChaos: The TrueConf Zero-Day That Turned Secure Updates Into a Government Espionage Backdoor

ID: 9ad6cf58-3426-56fd-9ce3-df423646166e

STIX ID: report--9ad6cf58-3426-56fd-9ce3-df423646166e

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-23

Author: Ddos

...
...

Check Point Research uncovered a zero-day (CVE-2026-3502) in the TrueConf on-premises update mechanism that was abused in the “TrueChaos” espionage campaign: attackers who compromised a central TrueConf server replaced legitimate updates with a weaponized client update that performed DLL side-loading (7z-x64.dll) and deployed a Havoc post‑exploitation implant to government networks in Southeast Asia; TrueConf has released a fix and users should upgrade the Windows client to 8.5.3 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.