Threat reportVulnerabilityTL-2026-0322

Operation TrueChaos: TrueConf Client 0-Day Exploitation via Supply Chain Update Hijack (CVE-2026-3502)

criticalMONITORING

Operation TrueChaos (TL-2026-0322), also tracked as Operation TrueChaos, is a critical-severity software vulnerability scored CVSS 7.8, first published 2026-04-06. It is linked to a China-nexus actor with medium confidence, affects TrueConf TrueConf Client for Windows, references 1 CVE (CVE-2026-3502), maps to 17 MITRE ATT&CK techniques (T1016, T1036, T1049), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
7.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0322

Threat ID
TL-2026-0322
Also known as
Operation TrueChaos
Severity
CRITICAL
CVSS
7.8 (CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government, military, critical-infrastructure, financial, defense
Target regions
Southeast Asia, Asia-Pacific
Detection rules
9
Indicators of compromise
20

Malware and tooling in Operation TrueChaos

Malware and tooling: ShadowPad, Havoc C2 Framework

How Operation TrueChaos works

Chinese-nexus threat actor exploits CVE-2026-3502, a code integrity bypass in TrueConf Client update mechanism, to deploy Havoc C2 implants against Southeast Asian government targets via DLL side-loading and UAC bypass. Added to CISA KEV on 2026-04-02 with federal remediation deadline of 2026-04-16.

Operation TrueChaos is a targeted cyber espionage campaign attributed with moderate confidence to a Chinese-nexus threat actor, discovered and reported by Check Point Research in March 2026. The campaign exploits CVE-2026-3502, a critical vulnerability in the TrueConf Windows client (versions prior to 8.5.3.884) where the application downloads and applies update code without performing integrity verification (CWE-494).

The attack chain begins with the threat actor gaining control of an on-premises TrueConf server operated by a Southeast Asian government IT organization. Once the server is compromised, the attacker replaces the legitimate client update package at the server's ClientInstFiles directory with a malicious Inno Setup executable. When connected TrueConf clients check for updates, they download and execute the weaponized installer without any integrity validation.

The malicious installer drops two key files to C:\ProgramData\PowerISO\: a legitimate copy of poweriso.exe and a trojanized 7z-x64.dll. The DLL side-loading technique abuses the legitimate poweriso.exe binary to load the malicious DLL, which serves as the primary implant. The 7z-x64.dll implant performs hands-on-keyboard reconnaissance using native Windows commands including tasklist for process enumeration and tracert 8.8.8.8 for network path discovery.

For privilege escalation, the attackers employ a UAC bypass technique exploiting the 32-bit SysWOW64 version of iscsicpl.exe, which is auto-elevated and vulnerable to DLL search-order hijacking. The attacker modifies the user PATH environment variable via HKCU\environment to hijack iscsiexe.dll resolution, enabling execution of a malicious DLL (iscsiexe.dll) with elevated privileges without triggering UAC prompts.

Persistence is established through the Windows registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck. Additional payloads are retrieved from an FTP server at 47.237.15.197 using curl with embedded credentials, with archives extracted using a legitimate copy of winrar.exe. The secondary payload iscsiexe.dll ensures continued execution of winexec.exe (a renamed poweriso.exe binary) for persistent backdoor operation.

The campaign deploys the open-source Havoc command-and-control framework for post-exploitation communication. C2 infrastructure is hosted on Alibaba Cloud and Tencent Cloud platforms. Notably, the same victim organization was targeted within the same timeframe by ShadowPad malware, a sophisticated backdoor historically associated with Chinese state-sponsored operations. The use of Havoc C2 has been previously attributed to Amaranth-Dragon, another Chinese-nexus threat actor targeting government and law enforcement agencies in Southeast Asia during 2025.

TrueConf serves approximately 100,000 organizations globally across government, military, critical infrastructure, banking, and enterprise sectors in Russia, East Asia, Europe, and the Americas. The vulnerability was patched in TrueConf Windows client version 8.5.3, released in March 2026. CISA added CVE-2026-3502 to the Known Exploited Vulnerabilities catalog on April 2, 2026, with a federal agency remediation deadline of April 16, 2026.

MITRE ATT&CK techniques used in TL-2026-0322

discovery

T1016 System Network Configuration Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1087 Account Discovery

defense-evasion

T1036 Masquerading

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port

initial-access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

persistence

T1547 Boot or Logon Autostart Execution

privilege-escalation

T1548 Abuse Elevation Control Mechanism

stealth

T1574 Hijack Execution Flow

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Affected products and versions in Operation TrueChaos

  • TrueConf — TrueConf Client for Windows
    Vulnerable versions: 8.1.0 through 8.5.2
    Fixed in: 8.5.3.884
  • TrueConf — TrueConf Server (on-premises)
    Vulnerable versions: All versions hosting vulnerable client updates
    Fixed in: Server hosting patched 8.5.3+ client packages

Remediation for Operation TrueChaos

Patches

  • Update TrueConf Windows client to version 8.5.3.884 or later
  • Apply vendor patch per CISA BOD 22-01 guidance by April 16, 2026

Immediate actions

  • Block C2 IPs at perimeter: 43.134.90.60, 43.134.52.221, 47.237.15.197
  • Scan endpoints for presence of C:\ProgramData\PowerISO\7z-x64.dll and %TEMP%\iscsiexe.dll
  • Check registry for HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck persistence
  • Inspect HKCU\environment PATH variable for unauthorized modifications
  • Audit TrueConf server update directories for tampered packages
  • Isolate any TrueConf servers pending investigation

Workarounds

  • Disable automatic updates in TrueConf client until patch is applied
  • Manually verify update package integrity before deployment
  • Discontinue use of TrueConf if patching is not feasible per CISA guidance

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading and UAC bypass patterns
  • Implement code signing verification for all software update mechanisms
  • Monitor for suspicious iscsicpl.exe execution and DLL search-order hijacking
  • Segment TrueConf servers from general network to limit lateral movement
  • Implement application whitelisting to prevent unauthorized DLL loading

CVEs associated with Operation TrueChaos

CVE-2026-3502

Weaknesses (CWE) in Operation TrueChaos

CWE-494

Timeline of Operation TrueChaos

  • Operation TrueChaos campaign begins with initial compromise of on-premises TrueConf server at Southeast Asian government organization
  • Active exploitation of CVE-2026-3502 observed — malicious updates distributed to connected TrueConf clients via compromised server
  • ShadowPad malware activity detected targeting the same victim organization, indicating coordinated Chinese-nexus operations
  • TrueConf releases version 8.5 update series including security fix in client version 8.5.3.884 addressing CVE-2026-3502
  • Check Point Research publishes detailed analysis of Operation TrueChaos campaign, disclosing CVE-2026-3502 and full attack chain with IOCs
  • CVE-2026-3502 published in NIST National Vulnerability Database with CVSS 7.8 base score
  • Multiple security news outlets (BleepingComputer, The Hacker News) report on Operation TrueChaos and CVE-2026-3502 exploitation
  • CISA adds CVE-2026-3502 to Known Exploited Vulnerabilities catalog with federal agency remediation deadline of April 16, 2026
  • CISA BOD 22-01 remediation deadline for federal agencies to patch or mitigate CVE-2026-3502
  • As of 2026-05-29, CVE-2026-3502 is patched in TrueConf client 8.5.3 (March 2026) and its CISA KEV deadline (Apr 16) has passed, with no reported exploitation beyond the original narrow Operation TrueChaos campaign. But the Chinese-nexus actor (Amaranth-Dragon/APT41 nexus) remains active with Havoc C2, so unpatched on-prem deployments warrant monitoring.

Sources cited for Operation TrueChaos

Detection coverage for TL-2026-0322

As of 2026-04-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0322 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats