Threat Advisory

Team46 Uses Chrome Exploit in Targeted Campaign

Threat: Vulnerability/Malware
Threat Actor Name: Team46 / TaxOff
Targeted Region: Russia
Threat Actor Region: NA
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Recent analysis revealed that TaxOff and Team46, previously thought to be separate threat actors, are actually the same group. This group targeted Russian government systems through finance-themed phishing emails that delivered a custom backdoor called Trinper. The attackers used advanced techniques, including exploiting the Chrome vulnerability CVE-2025-2783, which allows sandbox escape and privilege escalation. Trinper was designed to only run on specific systems, ensuring it worked only on intended victims. Both operations shared common traits—identical tools, delivery methods, and command-and-control infrastructure—confirming that TaxOff and Team46 are just different names for a single campaign.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Recent analysis revealed that TaxOff and Team46, previously thought to be separate threat actors, are actually the same group. This group targeted Russian government systems through finance-themed phishing emails that delivered a custom backdoor called Trinper. The attackers used advanced techniques, including exploiting the Chrome vulnerability CVE-2025-2783, which allows sandbox escape and privilege escalation. Trinper was designed to only run on specific systems, ensuring it worked only on intended victims. Both operations shared common traits—identical tools, delivery methods, and command-and-control infrastructure—confirming that TaxOff and Team46 are just different names for a single campaign.[emaillocker id="1283"]

The group exploited CVE-2025-2783 in Google Chrome to bypass security restrictions and gain initial access. After that, they used PowerShell scripts to download and execute Trinper, a multi-stage backdoor with data collection and remote control features. The malware was encrypted and tied to specific machine details, making analysis harder. The attackers also used CVE-2024-6473 in Yandex Browser to load malicious DLLs. Both campaigns used fake domains and shared almost identical PowerShell code, malware structure, and obfuscation tactics. These overlaps clearly show a single threat actor behind both names, using a range of tools to remain hidden.

This campaign demonstrates how a well-organized group combined phishing, browser exploits like CVE-2025-2783, and targeted malware to carry out cyber-espionage. By linking TaxOff and Team46, defenders gain better insight into the full scope of the threat. The group’s use of system-specific payloads and overlapping infrastructure shows a clear focus on stealth and precision. Organizations should monitor for suspicious PowerShell use, DLL hijacking behavior, and known C2 patterns. Though CVE-2025-2783 has been patched, the group’s techniques remain active, and understanding their full toolkit is key to defending against future attacks.

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Initial Access T1566.001 Phishing Spearphishing Attachment
Execution T1059.001 Command and Scripting Interpreter PowerShell
T1203 Exploitation for Client Execution CVE-2025-2783 (Chrome) & CVE-2024-6473 (Yandex)
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defense Evasion T1211 Exploitation for Defense Evasion
T1140 Deobfuscate/Decode Files or Information
Credential Access T1555 Credentials from Password Stores
Discovery T1082 System Information Discovery
Collection T1113 Screen Capture
Command and Control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel

 

MBC MAPPING:

Objective Behaviour ID Behaviour
Anti-Analysis B0001 Debugger Detection
Defense Evasion B0032 Executable Code Obfuscation
Execution E1059 Command and Scripting Interpreter
Persistence F0012 Registry Run Keys / Startup Folder
Discovery B0013 Analysis Tool Discovery
Collection E1056 Input Capture
Exfiltration B0030 C2 Communication

RECOMMENDATION:

  • We recommend you update Google Chrome to version 134.0.6998.178.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu