Check Point says attackers exploited CVE-2026-3502, a flaw in the TrueConf Windows client update validation mechanism, to push a malicious update through a trusted on-prem server and infect multiple Southeast Asian government entities. The campaign used DLL sideloading, UAC bypass, and infrastructure linked to Havoc C2, and the key artifacts to hunt for include trueconfwindowsupdate.exe, C:\ProgramData\PowerISO\poweriso.exe, 7z-x64.dll, iscsiexe.dll, and outbound activity to 43.134.90[.]60, 43.134.52[.]221, and 47.237.15[.]197. The flaw is fixed in TrueConf 8.5.3