Check Point noted that the targeting indicates the campaign was likely focused on espionage. TrueConf is used widely across organizations in Asia, Europe and the Americas, serving about 100,000 organizations globally. Check Point said it is used primarily by government, military, and critical infrastructure sectors “to ensure absolute data privacy and communication autonomy in secure or remote environments.” “In locations with poor or no internet connectivity, or during natural disasters when traditional networks are down, it facilitates essential coordination. By hosting the server on internal hardware, all audio, video, and chat traffic remains strictly contained on-site, with offline activation available for fully air-gapped systems.”
| Vendor | Product | Versions |
|---|---|---|
| trueconf | trueconf | TrueConf Client versions 8.1.0 through 8.5.2 |
Updated description with additional technical details, added patch release date as March, and included new IoCs and tags related to espionage.
Updated description with detailed attack mechanism and added patch version 8.5.3.
Updated description with new details about the attack and confirmed that exploits are available, along with a patch version.
Updated description with detailed attack information, added affected versions 8.1.0 to 8.5.2, changed severity to MEDIUM, updated CVSS estimate to 5.0, added new CWEs, confirmed exploit availability, added patch version 8.5.3, included new IoCs, added MITRE ATT&CK techniques T1203 and T1068, and included new tags.
Updated description with details about the zero-day exploitation and added new tags related to the attack campaign.
Initial creation