[ << ALL_FEED ]

TaxOff: it seems you have… a backdoor

More in General

📑 TaxOff: looks like you have… a backdoor

In the third quarter, specialists from the TI department of the Positive Technologies Expert Security Center (PT Expert Security Center, PT ESC) discovered a series of attacks targeting Russian government agencies. We were unable to establish links with any previously known groups using similar techniques.

😐 The main goals of the cybercriminals were espionage and establishing persistence in the system to enable subsequent attacks. We named this group TaxOff due to their use of emails on legal and financial topics as lures. In their attacks, the adversaries used a backdoor written in at least C++17, which we named Trinper due to an artifact used when connecting to the C2 server.

📩 The initial infection vector is phishing emails. We discovered several such emails: one contained a link to Yandex Disk with malicious content related to “1C,” while another contained a fake installer for software used to fill out income and expense declarations that government employees must submit each year. This software is updated annually and becomes a target for attackers distributing malware disguised as updates.

Trinper is a multithreaded backdoor written in C++ with flexible configuration, employing the template method as a design pattern, STL containers, and a buffer cache for improved performance.

🧐 A detailed analysis of the backdoor and the activities of the TaxOff group, as well as indicators of compromise, can be found in the report.

#TI #APT #IOC #Reverse
@ptescalator

More from ti_author

More from ti_author

More in General