EXECUTIVE SUMMARY:
Recent analysis revealed that TaxOff and Team46, previously thought to be separate threat actors, are actually the same group. This group targeted Russian government systems through finance-themed phishing emails that delivered a custom backdoor called Trinper. The attackers used advanced techniques, including exploiting the Chrome vulnerability CVE-2025-2783, which allows sandbox escape and privilege escalation. Trinper was designed to only run on specific systems, ensuring it worked only on intended victims. Both operations shared common traits—identical tools, delivery methods, and command-and-control infrastructure—confirming that TaxOff and Team46 are just different names for a single campaign.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Recent analysis revealed that TaxOff and Team46, previously thought to be separate threat actors, are actually the same group. This group targeted Russian government systems through finance-themed phishing emails that delivered a custom backdoor called Trinper. The attackers used advanced techniques, including exploiting the Chrome vulnerability CVE-2025-2783, which allows sandbox escape and privilege escalation. Trinper was designed to only run on specific systems, ensuring it worked only on intended victims. Both operations shared common traits—identical tools, delivery methods, and command-and-control infrastructure—confirming that TaxOff and Team46 are just different names for a single campaign.[emaillocker id="1283"]
The group exploited CVE-2025-2783 in Google Chrome to bypass security restrictions and gain initial access. After that, they used PowerShell scripts to download and execute Trinper, a multi-stage backdoor with data collection and remote control features. The malware was encrypted and tied to specific machine details, making analysis harder. The attackers also used CVE-2024-6473 in Yandex Browser to load malicious DLLs. Both campaigns used fake domains and shared almost identical PowerShell code, malware structure, and obfuscation tactics. These overlaps clearly show a single threat actor behind both names, using a range of tools to remain hidden.
This campaign demonstrates how a well-organized group combined phishing, browser exploits like CVE-2025-2783, and targeted malware to carry out cyber-espionage. By linking TaxOff and Team46, defenders gain better insight into the full scope of the threat. The group’s use of system-specific payloads and overlapping infrastructure shows a clear focus on stealth and precision. Organizations should monitor for suspicious PowerShell use, DLL hijacking behavior, and known C2 patterns. Though CVE-2025-2783 has been patched, the group’s techniques remain active, and understanding their full toolkit is key to defending against future attacks.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-Technique |
| Initial Access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| T1203 | Exploitation for Client Execution | CVE-2025-2783 (Chrome) & CVE-2024-6473 (Yandex) | |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defense Evasion | T1211 | Exploitation for Defense Evasion | — |
| T1140 | Deobfuscate/Decode Files or Information | — | |
| Credential Access | T1555 | Credentials from Password Stores | — |
| Discovery | T1082 | System Information Discovery | — |
| Collection | T1113 | Screen Capture | — |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | — |
MBC MAPPING:
| Objective | Behaviour ID | Behaviour |
| Anti-Analysis | B0001 | Debugger Detection |
| Defense Evasion | B0032 | Executable Code Obfuscation |
| Execution | E1059 | Command and Scripting Interpreter |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Discovery | B0013 | Analysis Tool Discovery |
| Collection | E1056 | Input Capture |
| Exfiltration | B0030 | C2 Communication |
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]