# Operation TrueChaos: CVE-2026-3502 TrueConf 0-Day Supply Chain Exploitation Targeting Southeast Asian Governments

> Chinese-nexus threat actor exploited CVE-2026-3502, an improper update validation vulnerability (CWE-494) in TrueConf Client versions prior to 8.5.3, to deliver trojanized updates via compromised on-premises servers. The campaign, dubbed Operation TrueChaos, leveraged DLL side-loading, UAC bypass, and Havoc C2 framework to compromise dozens of Southeast Asian government agencies.

- **Published:** 2026-03-31T12:00:00Z
- **Last reviewed:** 2026-03-31T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0302
- **ID:** TL-2026-0302
- **Severity:** HIGH (CVSS 7.8)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-3502

## Description

Operation TrueChaos represents a sophisticated supply chain attack targeting Southeast Asian government entities through the exploitation of CVE-2026-3502, a zero-day vulnerability in TrueConf's client update mechanism. TrueConf is a videoconferencing platform used by over 100,000 organizations globally, with significant adoption in government and enterprise environments.

The vulnerability stems from CWE-494 (Download of Code Without Integrity Check) — the TrueConf client downloads and applies application updates without performing integrity or authenticity verification. This design flaw allowed attackers who had compromised an on-premises TrueConf server operated by a governmental IT department to replace the legitimate update executable at C:\Program Files\TrueConf Server\ClientInstFiles\ with a trojanized Inno Setup installer.

When TrueConf client users were prompted to update, they downloaded the malicious package from https://{trueconf_server}/downlods/trueconf_client.exe. The installer appeared to upgrade the client from version 8.5.1 to 8.5.2 while silently deploying a multi-stage attack chain:

Stage 1 — DLL Side-Loading: The installer drops a legitimate copy of poweriso.exe alongside a malicious 7z-x64.dll into C:\ProgramData\PowerISO\. When poweriso.exe loads, it side-loads the malicious DLL which executes attacker code.

Stage 2 — Reconnaissance: The malicious DLL performs initial host reconnaissance by executing tasklist > cache and tracert 8.8.8.8 -h 5 to enumerate running processes and test network connectivity.

Stage 3 — Secondary Payload Retrieval: The malware connects to an FTP server at 47.237.15.197 to download update.7z, a password-protected 7z archive containing iscsiexe.dll, which is extracted to %AppData%\Roaming\Adobe\.

Stage 4 — UAC Bypass and Privilege Escalation: The attack modifies HKCU\environment PATH and triggers the legitimate Windows iSCSI Initiator (iscsicpl.exe) for a UAC bypass, allowing privilege escalation without user interaction.

Stage 5 — Persistence: Registry run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck is set to execute C:\ProgramData\PowerISO\PowerISO.exe on startup. The iscsiexe.dll loader functions as a custom persistence and privilege escalation tool, maintaining execution of a renamed copy of poweriso.exe (winexec.exe).

Stage 6 — C2 Communication: A Havoc C2 implant establishes command-and-control communication to attacker infrastructure hosted on Alibaba Cloud (43.134.90.60, 43.134.52.221) and Tencent Cloud (47.237.15.197). Havoc is an open-source post-exploitation framework that has been repeatedly abused by Chinese-nexus threat actors including Amaranth Dragon.

An additional artifact, rom.dat (an encrypted 7z archive), was observed but its purpose remains unknown at the time of analysis.

Attribution to a Chinese-nexus threat actor is assessed with moderate confidence based on: (1) TTPs consistent with Chinese cyber operations including DLL side-loading, (2) C2 infrastructure hosted on Chinese cloud providers (Alibaba, Tencent), (3) victimology aligned with Chinese strategic interests in Southeast Asia, and (4) concurrent ShadowPad malware activity targeting the same victims, suggesting overlap in operator tooling, shared access, or multiple China-aligned actors operating against the same target set.

Check Point Research conducted responsible disclosure to TrueConf, which developed a patch (version 8.5.3) prior to public disclosure on March 31, 2026.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1548 Abuse Elevation Control Mechanism
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1057 Process Discovery
- T1046 Network Service Discovery
- T1087 Account Discovery
- T1005 Data from Local System
- T1105 Ingress Tool Transfer
- T1071 Application Layer Protocol

## Sources

- [Check Point Research: Operation TrueChaos — 0-Day Exploitation Against Southeast Asian Government Targets](https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/)
- [NVD: CVE-2026-3502](https://nvd.nist.gov/vuln/detail/CVE-2026-3502)
- [TrueConf 8.5 Update Blog](https://trueconf.com/blog/update/trueconf-8-5)
- [MITRE ATT&CK: Supply Chain Compromise - T1195.002](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK: DLL Side-Loading - T1574.002](https://attack.mitre.org/techniques/T1574/002/)
- [Havoc C2 Framework GitHub Repository](https://github.com/HavocFramework/Havoc)
- [CWE-494: Download of Code Without Integrity Check](https://cwe.mitre.org/data/definitions/494.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0302
