Also known as: TaxOff, tracked as, Gh0stBins, sometimes the Gh0stCringe RAT, the same, Operation ForumTroll, Belarus, including media, academic, Team 46
Team 46 (a.k.a. TaxOff) demonstrates APT‑level sophistication by combining social engineering with advanced zero‑day exploitation to gain initial access. Their spear‑phishing campaigns use personalized short‑lived links or malicious attachments that trigger exploits within Google Chrome (CVE‑2025‑2783) or the Yandex Browser (CVE‑2024‑6473). Once compromised, a PowerShell‑based loader is downloaded and executed; it decrypts machine‑specific payloads using environmental guardrails such as firmware UUID. The loader delivers the Trinper backdoor along with auxiliary utilities (.NET tools such as dirlist.exe, ProcessList.exe) and may deploy additional spyware platforms (LeetAgent, Dante). The malware performs extensive data collection: keylogging (T1056.001), console screen capture (T1113), selective file exfiltration of documents and spreadsheets via HTTPS with domain fronting, as well as registry modifications and process injection (T1055) for persistence and privilege escalation. The code is heavily obfuscated, uses AMSI bypasses and debugger evasion, and self‑deletes to avoid detection. Team 46’s operational tactics illustrate a pattern of rapid initial compromise followed by thorough lateral movement and exfiltration. They maintain stealth through DLL hijacking mitigation indicators (Yandex CVE-2024‑6473), domain fronting, and persistence via registry run keys or COM hijacking. Their goal is to harvest intelligence from high‑value Russian and Belarusian targets while remaining undetected for extended periods. Key operational lessons include the use of browser zero‑days as a main delivery vector, reliance on PowerShell loaders for both download and execution, and sophisticated obfuscation techniques that neutralize modern EDR solutions if not specifically tuned to detect these patterns.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Team 46, also known as TaxOff, is a high‑sophistication APT that has targeted Russian and Belarusian government, media, academia, and critical infrastructure sectors since late 2024 using spear‑phishing, zero‑day browser exploits (CVE‑2025‑2783 in Chrome and CVE‑2024‑6473 in Yandex), and custom PowerShell loaders to deploy the Trinper backdoor. The group achieves full system compromise with keylogging, screen capture, selective file exfiltration over HTTPS with domain fronting, and employs anti‑analysis techniques such as AMSI bypasses, obfuscation, and self‑deletion for persistence.
Goals & Targeting
Team 46 operates primarily in an espionage context, seeking to compromise Russian and Belarusian entities across government agencies, media outlets, academia, financial institutions, defense contractors, telecommunications companies, and energy operators. Their strategy focuses on extracting strategic or politically sensitive information, leveraging insider documents and communications while avoiding overt disruption of services. The actor’s use of highly targeted phishing and zero‑day exploits indicates a focus on high‑value, mission‑critical data rather than widespread sabotage.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
18
Techniques
38
Tools
0
Campaigns
4
IOCs
0
Observed Data
10
Tactics