TrueChaos: The TrueConf Zero-Day That Turned Secure Updates Into a Government Espionage Backdoor
ID: 9ad6cf58-3426-56fd-9ce3-df423646166e
STIX ID: report--9ad6cf58-3426-56fd-9ce3-df423646166e
Feed Name: securityonline.info
Check Point Research uncovered a zero-day (CVE-2026-3502) in the TrueConf on-premises update mechanism that was abused in the “TrueChaos” espionage campaign: attackers who compromised a central TrueConf server replaced legitimate updates with a weaponized client update that performed DLL side-loading (7z-x64.dll) and deployed a Havoc post‑exploitation implant to government networks in Southeast Asia; TrueConf has released a fix and users should upgrade the Windows client to 8.5.3 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
