INTEL_REPORT
Check Point Research · published 3/31/2026, 1:16:50 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment. The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8…
https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets
sha256:a2154bd7b4366ea9fc23886f7640d58c0d0037baa19467db1a2a64d3c87d9ec1
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| domain | poweriso.exe | Open → |
| domain | 7z-x64.dll | Open → |
| domain | isciexe.dll | Open → |
| domain | winrar.exe | Open → |
| domain | iscsicpl.exe | Open → |
| domain | iscsiexe.dll | Open → |
| domain | 7z.exe | Open → |
| domain | rom.dat | Open → |
| domain | winexec.exe | Open → |
| domain | 7za.exe | Open → |
| domain | trueconf.exe | Open → |
| url | https://trueconf.com/docs/server/en/admin/info/ | Open → |
| md5 | 22e32bcf113326e366ac480b077067cf | Open → |
| md5 | 9b435ad985b733b64a6d5f39080f4ae0 | Open → |
| md5 | 248a4d7d4c48478dcbeade8f7dba80b3 | Open → |