Suspected China-linked threat actors have weaponized a high-severity zero-day flaw in the TrueConf client video conferencing software, tracked as CVE-2026-3502, to compromise multiple Southeast Asian government organizations with the Havoc command-and-control framework as part of the TrueChaos campaign, according to The Hacker News.
Attacks that began earlier this year involved the compromise of a central on-premises TrueConf server's update mechanism to inject a poisoned package that enabled the delivery of an illicit installer for a DLL implant, a report from Check Point Research showed. Apart from conducting reconnaissance and persistence, the DLL backdoor also facilitated the retrieval of another DLL that executed a benign binary that sideloads the Havoc C2 framework.
"By replacing a legitimate update with a malicious one, they turned the product's normal update flow into a malware distribution channel across multiple connected government networks," said researchers, who associated the campaign with Chinese attackers due to the involvement of DLL sideloading and Alibaba Cloud and Tencent-supported C2 infrastructure.
Attacks that began earlier this year involved the compromise of a central on-premises TrueConf server's update mechanism to inject a poisoned package that enabled the delivery of an illicit installer for a DLL implant, a report from Check Point Research showed. Apart from conducting reconnaissance and persistence, the DLL backdoor also facilitated the retrieval of another DLL that executed a benign binary that sideloads the Havoc C2 framework.
"By replacing a legitimate update with a malicious one, they turned the product's normal update flow into a malware distribution channel across multiple connected government networks," said researchers, who associated the campaign with Chinese attackers due to the involvement of DLL sideloading and Alibaba Cloud and Tencent-supported C2 infrastructure.




