logo

TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

ID: 4ab50df6-bdf9-5689-a709-277252ef2631

STIX ID: report--4ab50df6-bdf9-5689-a709-277252ef2631

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A high‑severity zero-day (CVE-2026-3502, CVSS 7.8) in TrueConf's update mechanism was exploited in the wild by the TrueChaos campaign to distribute tampered updates from compromised on‑premises TrueConf servers, enabling arbitrary code execution via DLL sideloading; the campaign targeted Southeast Asian government entities, delivered a DLL backdoor and likely the Havoc C2, used FTP and cloud infrastructure (including Alibaba/Tencent), and has been patched in TrueConf Windows client version 8.5.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.