Threat reportVulnerabilityTL-2026-0322
Operation TrueChaos: TrueConf Client 0-Day Exploitation via Supply Chain Update Hijack (CVE-2026-3502)
Operation TrueChaos (TL-2026-0322), also tracked as Operation TrueChaos, is a critical-severity software vulnerability scored CVSS 7.8, first published 2026-04-06. It is linked to a China-nexus actor with medium confidence, affects TrueConf TrueConf Client for Windows, references 1 CVE (CVE-2026-3502), maps to 17 MITRE ATT&CK techniques (T1016, T1036, T1049), and is covered by 9 detection rules and 20 indicators of compromise.
- CVSS
- 7.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-0322
- Threat ID
- TL-2026-0322
- Also known as
- Operation TrueChaos
- Severity
- CRITICAL
- CVSS
- 7.8 (CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, military, critical-infrastructure, financial, defense
- Target regions
- Southeast Asia, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Operation TrueChaos
Malware and tooling: ShadowPad, Havoc C2 Framework
How Operation TrueChaos works
Chinese-nexus threat actor exploits CVE-2026-3502, a code integrity bypass in TrueConf Client update mechanism, to deploy Havoc C2 implants against Southeast Asian government targets via DLL side-loading and UAC bypass. Added to CISA KEV on 2026-04-02 with federal remediation deadline of 2026-04-16.
Operation TrueChaos is a targeted cyber espionage campaign attributed with moderate confidence to a Chinese-nexus threat actor, discovered and reported by Check Point Research in March 2026. The campaign exploits CVE-2026-3502, a critical vulnerability in the TrueConf Windows client (versions prior to 8.5.3.884) where the application downloads and applies update code without performing integrity verification (CWE-494).
The attack chain begins with the threat actor gaining control of an on-premises TrueConf server operated by a Southeast Asian government IT organization. Once the server is compromised, the attacker replaces the legitimate client update package at the server's ClientInstFiles directory with a malicious Inno Setup executable. When connected TrueConf clients check for updates, they download and execute the weaponized installer without any integrity validation.
The malicious installer drops two key files to C:\ProgramData\PowerISO\: a legitimate copy of poweriso.exe and a trojanized 7z-x64.dll. The DLL side-loading technique abuses the legitimate poweriso.exe binary to load the malicious DLL, which serves as the primary implant. The 7z-x64.dll implant performs hands-on-keyboard reconnaissance using native Windows commands including tasklist for process enumeration and tracert 8.8.8.8 for network path discovery.
For privilege escalation, the attackers employ a UAC bypass technique exploiting the 32-bit SysWOW64 version of iscsicpl.exe, which is auto-elevated and vulnerable to DLL search-order hijacking. The attacker modifies the user PATH environment variable via HKCU\environment to hijack iscsiexe.dll resolution, enabling execution of a malicious DLL (iscsiexe.dll) with elevated privileges without triggering UAC prompts.
Persistence is established through the Windows registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck. Additional payloads are retrieved from an FTP server at 47.237.15.197 using curl with embedded credentials, with archives extracted using a legitimate copy of winrar.exe. The secondary payload iscsiexe.dll ensures continued execution of winexec.exe (a renamed poweriso.exe binary) for persistent backdoor operation.
The campaign deploys the open-source Havoc command-and-control framework for post-exploitation communication. C2 infrastructure is hosted on Alibaba Cloud and Tencent Cloud platforms. Notably, the same victim organization was targeted within the same timeframe by ShadowPad malware, a sophisticated backdoor historically associated with Chinese state-sponsored operations. The use of Havoc C2 has been previously attributed to Amaranth-Dragon, another Chinese-nexus threat actor targeting government and law enforcement agencies in Southeast Asia during 2025.
TrueConf serves approximately 100,000 organizations globally across government, military, critical infrastructure, banking, and enterprise sectors in Russia, East Asia, Europe, and the Americas. The vulnerability was patched in TrueConf Windows client version 8.5.3, released in March 2026. CISA added CVE-2026-3502 to the Known Exploited Vulnerabilities catalog on April 2, 2026, with a federal agency remediation deadline of April 16, 2026.
MITRE ATT&CK techniques used in TL-2026-0322
discovery
T1016 System Network Configuration Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1087 Account Discovery
defense-evasion
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
initial-access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
persistence
T1547 Boot or Logon Autostart Execution
privilege-escalation
T1548 Abuse Elevation Control Mechanism
stealth
resource-development
Affected products and versions in Operation TrueChaos
- TrueConf — TrueConf Client for Windows
Vulnerable versions: 8.1.0 through 8.5.2
Fixed in: 8.5.3.884 - TrueConf — TrueConf Server (on-premises)
Vulnerable versions: All versions hosting vulnerable client updates
Fixed in: Server hosting patched 8.5.3+ client packages
Remediation for Operation TrueChaos
Patches
- Update TrueConf Windows client to version 8.5.3.884 or later
- Apply vendor patch per CISA BOD 22-01 guidance by April 16, 2026
Immediate actions
- Block C2 IPs at perimeter: 43.134.90.60, 43.134.52.221, 47.237.15.197
- Scan endpoints for presence of C:\ProgramData\PowerISO\7z-x64.dll and %TEMP%\iscsiexe.dll
- Check registry for HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck persistence
- Inspect HKCU\environment PATH variable for unauthorized modifications
- Audit TrueConf server update directories for tampered packages
- Isolate any TrueConf servers pending investigation
Workarounds
- Disable automatic updates in TrueConf client until patch is applied
- Manually verify update package integrity before deployment
- Discontinue use of TrueConf if patching is not feasible per CISA guidance
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading and UAC bypass patterns
- Implement code signing verification for all software update mechanisms
- Monitor for suspicious iscsicpl.exe execution and DLL search-order hijacking
- Segment TrueConf servers from general network to limit lateral movement
- Implement application whitelisting to prevent unauthorized DLL loading
CVEs associated with Operation TrueChaos
Weaknesses (CWE) in Operation TrueChaos
Timeline of Operation TrueChaos
- Operation TrueChaos campaign begins with initial compromise of on-premises TrueConf server at Southeast Asian government organization
- Active exploitation of CVE-2026-3502 observed — malicious updates distributed to connected TrueConf clients via compromised server
- ShadowPad malware activity detected targeting the same victim organization, indicating coordinated Chinese-nexus operations
- TrueConf releases version 8.5 update series including security fix in client version 8.5.3.884 addressing CVE-2026-3502
- Check Point Research publishes detailed analysis of Operation TrueChaos campaign, disclosing CVE-2026-3502 and full attack chain with IOCs
- CVE-2026-3502 published in NIST National Vulnerability Database with CVSS 7.8 base score
- Multiple security news outlets (BleepingComputer, The Hacker News) report on Operation TrueChaos and CVE-2026-3502 exploitation
- CISA adds CVE-2026-3502 to Known Exploited Vulnerabilities catalog with federal agency remediation deadline of April 16, 2026
- CISA BOD 22-01 remediation deadline for federal agencies to patch or mitigate CVE-2026-3502
- As of 2026-05-29, CVE-2026-3502 is patched in TrueConf client 8.5.3 (March 2026) and its CISA KEV deadline (Apr 16) has passed, with no reported exploitation beyond the original narrow Operation TrueChaos campaign. But the Chinese-nexus actor (Amaranth-Dragon/APT41 nexus) remains active with Havoc C2, so unpatched on-prem deployments warrant monitoring.
Sources cited for Operation TrueChaos
- Check Point Research: Operation TrueChaos — 0-Day Exploitation Against Southeast Asian Government Targets
- CISA KEV Entry — CVE-2026-3502
- NVD — CVE-2026-3502
- TrueConf 8.5 Security Update
- Check Point Blog: Operation TrueChaos — TrueConf Zero-Day Supply-Chain Attack
- The Hacker News: TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks
- BleepingComputer: Hackers Exploit TrueConf Zero-Day to Push Malicious Software Updates
- Help Net Security: TrueConf Zero-Day Vulnerability Exploited to Target Government Networks
- The Record: CISA Gives Agencies Two Weeks to Patch Video Conferencing Bug Exploited by Chinese Hackers
- Security Affairs: CISA Adds TrueConf Client Flaw to Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-0322
As of 2026-04-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0322 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.