Team46 and TaxOff: two sides of the same coin

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Team46 and TaxOff: Two Sides of the Same Coin😑
In March 2025, specialists from the TI department of the Positive Technologies Expert Security Center (PT Expert Security Center, PT ESC) investigated an attack that used a zero-day vulnerability CVE-2025-2783 in the Chrome browser, registered around the same time. The use of this vulnerability and the attack itself were described by researchers from Kaspersky Lab, but the subsequent infection chain remained unattributed.
🪞 The report describes the attribution of this attack to the TaxOff group, which we have written about previously. Additionally, data is provided that allows us to consider another group we previously identified, Team46, and TaxOff as the same group.
The initial attack vector was a phishing email containing a link. When the victim clicked the link, they activated a one-click exploit, leading to the installation of the Trinper backdoor from the TaxOff group on the compromised system. In this attack, a backdoor from the Team46 group was discovered.
The Team46 group was previously observed in attacks using DLL-Hijacking for Yandex Browser (CVE-2024-6473).
📖 Read more on our website.
#TI #APT #cve
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



