Threat reportSupply ChainTL-2026-0302
Operation TrueChaos: CVE-2026-3502 TrueConf 0-Day Supply Chain Exploitation Targeting Southeast Asian Governments
Operation TrueChaos (TL-2026-0302), also tracked as Operation TrueChaos, is a high-severity supply-chain compromise scored CVSS 7.8, first published 2026-03-31. It is linked to a China-nexus actor with medium confidence, affects TrueConf TrueConf Client, references 1 CVE (CVE-2026-3502), maps to 13 MITRE ATT&CK techniques (T1005, T1036, T1046), and is covered by 9 detection rules and 22 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-0302
- Threat ID
- TL-2026-0302
- Also known as
- Operation TrueChaos
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L)
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, defense, critical-infrastructure
- Target regions
- Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Operation TrueChaos
Malware and tooling: ShadowPad, Havoc, Inno Setup
How Operation TrueChaos works
Chinese-nexus threat actor exploited CVE-2026-3502, an improper update validation vulnerability (CWE-494) in TrueConf Client versions prior to 8.5.3, to deliver trojanized updates via compromised on-premises servers. The campaign, dubbed Operation TrueChaos, leveraged DLL side-loading, UAC bypass, and Havoc C2 framework to compromise dozens of Southeast Asian government agencies.
Operation TrueChaos represents a sophisticated supply chain attack targeting Southeast Asian government entities through the exploitation of CVE-2026-3502, a zero-day vulnerability in TrueConf's client update mechanism. TrueConf is a videoconferencing platform used by over 100,000 organizations globally, with significant adoption in government and enterprise environments.
The vulnerability stems from CWE-494 (Download of Code Without Integrity Check) — the TrueConf client downloads and applies application updates without performing integrity or authenticity verification. This design flaw allowed attackers who had compromised an on-premises TrueConf server operated by a governmental IT department to replace the legitimate update executable at C:\Program Files\TrueConf Server\ClientInstFiles\ with a trojanized Inno Setup installer.
When TrueConf client users were prompted to update, they downloaded the malicious package from https://{trueconf_server}/downlods/trueconf_client.exe. The installer appeared to upgrade the client from version 8.5.1 to 8.5.2 while silently deploying a multi-stage attack chain:
Stage 1 — DLL Side-Loading: The installer drops a legitimate copy of poweriso.exe alongside a malicious 7z-x64.dll into C:\ProgramData\PowerISO\. When poweriso.exe loads, it side-loads the malicious DLL which executes attacker code.
Stage 2 — Reconnaissance: The malicious DLL performs initial host reconnaissance by executing tasklist > cache and tracert 8.8.8.8 -h 5 to enumerate running processes and test network connectivity.
Stage 3 — Secondary Payload Retrieval: The malware connects to an FTP server at 47.237.15.197 to download update.7z, a password-protected 7z archive containing iscsiexe.dll, which is extracted to %AppData%\Roaming\Adobe\.
Stage 4 — UAC Bypass and Privilege Escalation: The attack modifies HKCU\environment PATH and triggers the legitimate Windows iSCSI Initiator (iscsicpl.exe) for a UAC bypass, allowing privilege escalation without user interaction.
Stage 5 — Persistence: Registry run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck is set to execute C:\ProgramData\PowerISO\PowerISO.exe on startup. The iscsiexe.dll loader functions as a custom persistence and privilege escalation tool, maintaining execution of a renamed copy of poweriso.exe (winexec.exe).
Stage 6 — C2 Communication: A Havoc C2 implant establishes command-and-control communication to attacker infrastructure hosted on Alibaba Cloud (43.134.90.60, 43.134.52.221) and Tencent Cloud (47.237.15.197). Havoc is an open-source post-exploitation framework that has been repeatedly abused by Chinese-nexus threat actors including Amaranth Dragon.
An additional artifact, rom.dat (an encrypted 7z archive), was observed but its purpose remains unknown at the time of analysis.
Attribution to a Chinese-nexus threat actor is assessed with moderate confidence based on: (1) TTPs consistent with Chinese cyber operations including DLL side-loading, (2) C2 infrastructure hosted on Chinese cloud providers (Alibaba, Tencent), (3) victimology aligned with Chinese strategic interests in Southeast Asia, and (4) concurrent ShadowPad malware activity targeting the same victims, suggesting overlap in operator tooling, shared access, or multiple China-aligned actors operating against the same target set.
Check Point Research conducted responsible disclosure to TrueConf, which developed a patch (version 8.5.3) prior to public disclosure on March 31, 2026.
MITRE ATT&CK techniques used in TL-2026-0302
collection
defense-evasion
T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
discovery
T1046 Network Service Discovery; T1057 Process Discovery; T1087 Account Discovery
execution
T1059 Command and Scripting Interpreter
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
initial-access
persistence
T1547 Boot or Logon Autostart Execution
privilege-escalation
T1548 Abuse Elevation Control Mechanism
stealth
Affected products and versions in Operation TrueChaos
- TrueConf — TrueConf Client
Vulnerable versions: < 8.5.3; 8.5.1; 8.5.2
Fixed in: 8.5.3 - TrueConf — TrueConf Server
Vulnerable versions: On-premises deployments (version unspecified)
Fixed in: Contact vendor for patched version
Remediation for Operation TrueChaos
Patches
- Upgrade TrueConf Client to version 8.5.3 or later (patches CVE-2026-3502)
- Apply TrueConf Server updates to prevent update mechanism abuse
Immediate actions
- Block C2 IPs 43.134.90.60, 43.134.52.221, and 47.237.15.197 at perimeter firewall
- Hunt for C:\ProgramData\PowerISO\poweriso.exe and 7z-x64.dll on all endpoints
- Check registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck for unauthorized entries
- Inspect TrueConf Server ClientInstFiles directory for unauthorized modifications
- Quarantine any systems with confirmed IOC matches
Workarounds
- Disable automatic updates in TrueConf Client until patching is complete
- Block FTP outbound traffic to untrusted destinations
- Restrict execution of poweriso.exe and iscsicpl.exe via AppLocker or WDAC policies
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading and UAC bypass patterns
- Implement application whitelisting to prevent unauthorized executables in ProgramData
- Monitor FTP connections to external IPs from internal hosts
- Audit TrueConf server access controls and implement network segmentation
- Establish code signing verification for all software updates
CVEs associated with Operation TrueChaos
Weaknesses (CWE) in Operation TrueChaos
Timeline of Operation TrueChaos
- Operation TrueChaos campaign begins targeting Southeast Asian government entities via compromised TrueConf on-premises server
- Check Point Research identifies malicious activity associated with trojanized TrueConf updates distributed to dozens of government agencies
- Full attack chain analysis completed including DLL side-loading, UAC bypass, and Havoc C2 deployment; concurrent ShadowPad activity identified
- Check Point Research conducts responsible disclosure to TrueConf, notifying vendor of CVE-2026-3502
- TrueConf releases version 8.5.3 with integrity and authenticity checks for the update mechanism, patching CVE-2026-3502
- CVE-2026-3502 published on NVD with CVSS 7.8 HIGH rating (CWE-494: Download of Code Without Integrity Check)
- Check Point Research publishes full technical analysis of Operation TrueChaos including IOCs, attack chain, and attribution assessment
- As of 2026-05-29, CVE-2026-3502 is patched in TrueConf 8.5.3 and CISA's KEV remediation deadline (Apr 16) has passed, but it remains a live concern: it sits in the KEV catalog for confirmed in-the-wild exploitation, unpatched clients stay exploitable, and the Chinese-nexus Havoc/Amaranth Dragon actor persists.
Sources cited for Operation TrueChaos
- Check Point Research: Operation TrueChaos — 0-Day Exploitation Against Southeast Asian Government Targets
- NVD: CVE-2026-3502
- TrueConf 8.5 Update Blog
- MITRE ATT&CK: Supply Chain Compromise - T1195.002
- MITRE ATT&CK: DLL Side-Loading - T1574.002
- Havoc C2 Framework GitHub Repository
- CWE-494: Download of Code Without Integrity Check
Detection coverage for TL-2026-0302
As of 2026-03-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0302 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.