TrueConf Zero-Day Exploited in Asian Government Attacks

2026-04-03T19:24:09Z6f5d01d586da81f412e7a1c7624c4c28e468a8c41a5f1155dacc842787929899
android rootkitanthropicapplechinese threat actorclaude codecredential harvestingcritical vulnerabilitycryptocurrency theftdarksworddriftexploit kitmobile attack surfacenexus listenernorth koreaprivilege escalationransomwarereact2shellreconnaissancesharefilet-mobiletrueconfunauthenticated RCEvideo conferencingzero-day

What happened

SecurityWeek coverage highlights multiple active, high-impact incidents and vulnerabilities. A zero-day in the TrueConf video conferencing platform is being exploited by a Chinese threat actor against Asian government targets for reconnaissance, privilege escalation, and payload execution. Critical ShareFile flaws can be chained to bypass authentication and achieve unauthenticated RCE/upload of arbitrary files; React2Shell has been used in a large-scale credential-harvesting campaign (750+ systems). Additional notable items include a $285M drain from Drift attributed to North Korean attackers,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
6f5d01d586da81f412e7a1c7624c4c28e468a8c41a5f1155dacc842787929899
Enrichment time
2026-04-03T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.