# Operation TrueChaos: TrueConf Client 0-Day Exploitation via Supply Chain Update Hijack (CVE-2026-3502)

> Chinese-nexus threat actor exploits CVE-2026-3502, a code integrity bypass in TrueConf Client update mechanism, to deploy Havoc C2 implants against Southeast Asian government targets via DLL side-loading and UAC bypass. Added to CISA KEV on 2026-04-02 with federal remediation deadline of 2026-04-16.

- **Published:** 2026-04-06T12:00:00Z
- **Last reviewed:** 2026-04-06T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0322
- **ID:** TL-2026-0322
- **Severity:** CRITICAL (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-3502

## Description

Operation TrueChaos is a targeted cyber espionage campaign attributed with moderate confidence to a Chinese-nexus threat actor, discovered and reported by Check Point Research in March 2026. The campaign exploits CVE-2026-3502, a critical vulnerability in the TrueConf Windows client (versions prior to 8.5.3.884) where the application downloads and applies update code without performing integrity verification (CWE-494).

The attack chain begins with the threat actor gaining control of an on-premises TrueConf server operated by a Southeast Asian government IT organization. Once the server is compromised, the attacker replaces the legitimate client update package at the server's ClientInstFiles directory with a malicious Inno Setup executable. When connected TrueConf clients check for updates, they download and execute the weaponized installer without any integrity validation.

The malicious installer drops two key files to C:\ProgramData\PowerISO\: a legitimate copy of poweriso.exe and a trojanized 7z-x64.dll. The DLL side-loading technique abuses the legitimate poweriso.exe binary to load the malicious DLL, which serves as the primary implant. The 7z-x64.dll implant performs hands-on-keyboard reconnaissance using native Windows commands including tasklist for process enumeration and tracert 8.8.8.8 for network path discovery.

For privilege escalation, the attackers employ a UAC bypass technique exploiting the 32-bit SysWOW64 version of iscsicpl.exe, which is auto-elevated and vulnerable to DLL search-order hijacking. The attacker modifies the user PATH environment variable via HKCU\environment to hijack iscsiexe.dll resolution, enabling execution of a malicious DLL (iscsiexe.dll) with elevated privileges without triggering UAC prompts.

Persistence is established through the Windows registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck. Additional payloads are retrieved from an FTP server at 47.237.15.197 using curl with embedded credentials, with archives extracted using a legitimate copy of winrar.exe. The secondary payload iscsiexe.dll ensures continued execution of winexec.exe (a renamed poweriso.exe binary) for persistent backdoor operation.

The campaign deploys the open-source Havoc command-and-control framework for post-exploitation communication. C2 infrastructure is hosted on Alibaba Cloud and Tencent Cloud platforms. Notably, the same victim organization was targeted within the same timeframe by ShadowPad malware, a sophisticated backdoor historically associated with Chinese state-sponsored operations. The use of Havoc C2 has been previously attributed to Amaranth-Dragon, another Chinese-nexus threat actor targeting government and law enforcement agencies in Southeast Asia during 2025.

TrueConf serves approximately 100,000 organizations globally across government, military, critical infrastructure, banking, and enterprise sectors in Russia, East Asia, Europe, and the Americas. The vulnerability was patched in TrueConf Windows client version 8.5.3, released in March 2026. CISA added CVE-2026-3502 to the Known Exploited Vulnerabilities catalog on April 2, 2026, with a federal agency remediation deadline of April 16, 2026.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1548 Abuse Elevation Control Mechanism
- T1036 Masquerading
- T1057 Process Discovery
- T1049 System Network Connections Discovery
- T1016 System Network Configuration Discovery
- T1087 Account Discovery
- T1071 Application Layer Protocol
- T1571 Non-Standard Port
- T1105 Ingress Tool Transfer
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities

## Sources

- [Check Point Research: Operation TrueChaos — 0-Day Exploitation Against Southeast Asian Government Targets](https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/)
- [CISA KEV Entry — CVE-2026-3502](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3502)
- [NVD — CVE-2026-3502](https://nvd.nist.gov/vuln/detail/CVE-2026-3502)
- [TrueConf 8.5 Security Update](https://trueconf.com/blog/update/trueconf-8-5)
- [Check Point Blog: Operation TrueChaos — TrueConf Zero-Day Supply-Chain Attack](https://blog.checkpoint.com/research/when-trusted-software-updates-become-the-attack-vector-inside-operation-truechaos-and-a-new-zero-day-vulnerability-in-a-popular-collaboration-tool/)
- [The Hacker News: TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks](https://thehackernews.com/2026/03/trueconf-zero-day-exploited-in-attacks.html)
- [BleepingComputer: Hackers Exploit TrueConf Zero-Day to Push Malicious Software Updates](https://www.bleepingcomputer.com/news/security/hackers-exploit-trueconf-zero-day-to-push-malicious-software-updates/)
- [Help Net Security: TrueConf Zero-Day Vulnerability Exploited to Target Government Networks](https://www.helpnetsecurity.com/2026/04/02/trueconf-zero-day-vulnerability-cyber-espionage/)
- [The Record: CISA Gives Agencies Two Weeks to Patch Video Conferencing Bug Exploited by Chinese Hackers](https://therecord.media/trueconf-cyberattack-cisa-hackers)
- [Security Affairs: CISA Adds TrueConf Client Flaw to Known Exploited Vulnerabilities Catalog](https://securityaffairs.com/190341/security/u-s-cisa-adds-a-flaw-in-trueconf-client-to-its-known-exploited-vulnerabilities-catalog.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0322
