PULSE NAME
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets
WHITE Chinese-nexus threat actor AlienVault 2026-03-31 Modified: 2026-03-31
3
IOCs
LOW VOLUME
A zero-day vulnerability in the TrueConf client application, CVE-2026-3502, was exploited in a targeted campaign against government entities in Southeast Asia. The flaw allows attackers controlling an on-premises TrueConf server to distribute and execute arbitrary files across connected endpoints. The campaign, dubbed 'TrueChaos', abused the trusted update channel to deliver malware to multiple government agencies. The attack likely involved a Chinese-nexus threat actor and utilized the Havoc post-exploitation framework. The vulnerability stems from inadequate validation in the update process, enabling malicious updates to be distributed through a centrally managed server. TrueConf has since released a fix in version 8.5.3 of their Windows client.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Havoc
Indicators of Compromise (3)
All FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 22e32bcf113326e366ac480b077067cf 2026-03-31
FileHash-MD5 248a4d7d4c48478dcbeade8f7dba80b3 2026-03-31
FileHash-MD5 9b435ad985b733b64a6d5f39080f4ae0 2026-03-31