← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets
A zero-day vulnerability in the TrueConf client application, CVE-2026-3502, was exploited in a targeted campaign against government entities in Southeast Asia. The flaw allows attackers controlling an on-premises TrueConf server to distribute and execute arbitrary files across connected endpoints. The campaign, dubbed 'TrueChaos', abused the trusted update channel to deliver malware to multiple government agencies. The attack likely involved a Chinese-nexus threat actor and utilized the Havoc post-exploitation framework. The vulnerability stems from inadequate validation in the update process, enabling malicious updates to be distributed through a centrally managed server. TrueConf has since released a fix in version 8.5.3 of their Windows client.
MITRE ATT&CK & Malware Families
Indicators of Compromise (3)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 22e32bcf113326e366ac480b077067cf | — | 2026-03-31 | |
| FileHash-MD5 | 248a4d7d4c48478dcbeade8f7dba80b3 | — | 2026-03-31 | |
| FileHash-MD5 | 9b435ad985b733b64a6d5f39080f4ae0 | — | 2026-03-31 |