Havoc C2 is a command-and-control framework that was deployed in campaigns exploiting CVE-2026-3502, a zero-day in the TrueConf client. The attacks targeted government entities in Southeast Asia. Havoc C2 provides attackers with remote control over compromised systems.