Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Team46

Also known as: TaxOff, tracked as, Gh0stBins, sometimes the Gh0stCringe RAT, the same, Operation ForumTroll, Belarus, including media, academic, Team 46

Description

Team 46 (a.k.a. TaxOff) demonstrates APT‑level sophistication by combining social engineering with advanced zero‑day exploitation to gain initial access. Their spear‑phishing campaigns use personalized short‑lived links or malicious attachments that trigger exploits within Google Chrome (CVE‑2025‑2783) or the Yandex Browser (CVE‑2024‑6473). Once compromised, a PowerShell‑based loader is downloaded and executed; it decrypts machine‑specific payloads using environmental guardrails such as firmware UUID. The loader delivers the Trinper backdoor along with auxiliary utilities (.NET tools such as dirlist.exe, ProcessList.exe) and may deploy additional spyware platforms (LeetAgent, Dante). The malware performs extensive data collection: keylogging (T1056.001), console screen capture (T1113), selective file exfiltration of documents and spreadsheets via HTTPS with domain fronting, as well as registry modifications and process injection (T1055) for persistence and privilege escalation. The code is heavily obfuscated, uses AMSI bypasses and debugger evasion, and self‑deletes to avoid detection. Team 46’s operational tactics illustrate a pattern of rapid initial compromise followed by thorough lateral movement and exfiltration. They maintain stealth through DLL hijacking mitigation indicators (Yandex CVE-2024‑6473), domain fronting, and persistence via registry run keys or COM hijacking. Their goal is to harvest intelligence from high‑value Russian and Belarusian targets while remaining undetected for extended periods. Key operational lessons include the use of browser zero‑days as a main delivery vector, reliance on PowerShell loaders for both download and execution, and sophisticated obfuscation techniques that neutralize modern EDR solutions if not specifically tuned to detect these patterns.

Goals & Targeting

Targeted Sectors

Government
Financial services
Media
Education
Defense
Telecommunications
Energy

Targeted Countries / Regions

RU
BY

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 1 day ago

Executive Summary

Team 46, also known as TaxOff, is a high‑sophistication APT that has targeted Russian and Belarusian government, media, academia, and critical infrastructure sectors since late 2024 using spear‑phishing, zero‑day browser exploits (CVE‑2025‑2783 in Chrome and CVE‑2024‑6473 in Yandex), and custom PowerShell loaders to deploy the Trinper backdoor. The group achieves full system compromise with keylogging, screen capture, selective file exfiltration over HTTPS with domain fronting, and employs anti‑analysis techniques such as AMSI bypasses, obfuscation, and self‑deletion for persistence.

Goals & Targeting

Team 46 operates primarily in an espionage context, seeking to compromise Russian and Belarusian entities across government agencies, media outlets, academia, financial institutions, defense contractors, telecommunications companies, and energy operators. Their strategy focuses on extracting strategic or politically sensitive information, leveraging insider documents and communications while avoiding overt disruption of services. The actor’s use of highly targeted phishing and zero‑day exploits indicates a focus on high‑value, mission‑critical data rather than widespread sabotage.

Enhanced Description

Key Capabilities

  • Spearphishing emails with malicious attachments or personalized short‑lived links targeting Chrome and Yandex browsers
  • Zero‑day exploitation (CVE‑2025‑2783 Google Chrome sandbox escape; CVE‑2024‑6473 Yandex Browser DLL hijacking) for initial access
  • PowerShell‑based loaders delivered via shortcut (.lnk) in ZIP attachments or direct download
  • Encrypted, machine‑specific payloads decrypted using firmware UUID guardrails
  • Persistence through registry run keys/startup folder and COM hijacking
  • Keylogging (T1056.001), screen capture (T1113), file selection of .doc,/xlsx,.ppt,.pdf for exfiltration
  • Process injection (T1055) and obfuscated delivery with AMSI bypasses and debugger evasion
  • Domain fronting HTTPS C2 traffic to conceal command and control, along with file‑level encryption
  • DLL hijacking mitigation indicators and environment checks for anti‑analysis

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. thehackernews.com — Cited by web research for: the same
  2. www.rescana.com — Cited by web research for: Operation ForumTroll
  3. advisory.eventussecurity.com — Cited by web research for: T1566.001
  4. global.ptsecurity.com — Cited by web research for: curl

Intel Summary

18

Techniques

38

Tools

0

Campaigns

4

IOCs

0

Observed Data

10

Tactics

Tags

APT
Phishing
Zero-Day Exploitation
Backdoor / C2
Government Targeting
espionage
nation-state
Russian Federation
government-targeted
academic-targeted
media-targeted

Details

Type
Unknown
Primary Motivation
Espionage
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.