TrueConf Zero-Day Exploited in Asian Government Attacks
2026-04-03T19:24:09Z•6f5d01d586da81f412e7a1c7624c4c28e468a8c41a5f1155dacc842787929899
android rootkitanthropicapplechinese threat actorclaude codecredential harvestingcritical vulnerabilitycryptocurrency theftdarksworddriftexploit kitmobile attack surfacenexus listenernorth koreaprivilege escalationransomwarereact2shellreconnaissancesharefilet-mobiletrueconfunauthenticated RCEvideo conferencingzero-day
What happened
SecurityWeek coverage highlights multiple active, high-impact incidents and vulnerabilities. A zero-day in the TrueConf video conferencing platform is being exploited by a Chinese threat actor against Asian government targets for reconnaissance, privilege escalation, and payload execution. Critical ShareFile flaws can be chained to bypass authentication and achieve unauthenticated RCE/upload of arbitrary files; React2Shell has been used in a large-scale credential-harvesting campaign (750+ systems). Additional notable items include a $285M drain from Drift attributed to North Korean attackers,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 6f5d01d586da81f412e7a1c7624c4c28e468a8c41a5f1155dacc842787929899
- Enrichment time
- 2026-04-03T19:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.