‘By replacing a legitimate update with a malicious one, they turned the product’s update flow into a malware distribution channel’: Experts find flaw in TrueConf video conferencing tool used by governments, military


  • Sophisticated supply chain attack exploited the TrueConf update process
  • Frames deployed for espionage operations
  • Vulnerability fixed with new TrueConf version 8.5.3

Southeast Asian governments were recently hit by a highly sophisticated supply chain attack as part of a wider cyberespionage campaign that experts believe is the work of the Chinese government.

Security researchers Check Point detailed their findings on Operation TrueChaos, a campaign revolving around a zero-day vulnerability in TrueConf, a video conferencing and collaboration platform that runs either in the cloud or on a company’s own servers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top