216.73.217.80

Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets

· Published 31/03/2026 18:35 · Modified 31/03/2026 18:49

Export JSON

Essential information

Published
31/03/2026 18:35
Modified
31/03/2026 18:49
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
cve-2026-3502 dll sideloading government targets havoc southeast asia trueconf zero-day
Tags
2026-03-31 CVE-2026-3502 dll sideloading government targets havoc southeast asia trueconf zero-day
Related entities
1 vulnerabilities (cve), 1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 1 others

Description

A vulnerability in the client application, , was exploited in a targeted campaign against government entities in . The flaw allows attackers controlling an on-premises server to distribute and execute arbitrary files across connected endpoints. The campaign, dubbed 'TrueChaos', abused the trusted update channel to deliver malware to multiple government agencies. The attack likely involved a Chinese-nexus threat actor and utilized the post-exploitation framework. The vulnerability stems from inadequate validation in the update process, enabling malicious updates to be distributed through a centrally managed server. has since released a fix in version 8.5.3 of their Windows client.

External references