logo

Hackers exploit TrueConf zero-day to push malicious software updates

ID: fd2c9153-d673-51ae-98fe-bcfa10b8cc17

STIX ID: report--fd2c9153-d673-51ae-98fe-bcfa10b8cc17

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-04-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Check Point disclosed active exploitation of a TrueConf zero-day (CVE-2026-3502) that abuses a missing integrity check in the update mechanism to distribute malicious updates and execute arbitrary files on connected endpoints; the "TrueChaos" campaign is attributed with moderate confidence to a Chinese-nexus actor targeting government entities in Southeast Asia, leveraging DLL sideloading, UAC bypass, and likely the Havoc C2 framework, affecting TrueConf versions 8.1.0–8.5.2 and patched in 8.5.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.