A security vulnerability in Google Chrome was exploited by the threat group TaxOff to deploy the Trinper backdoor through a phishing campaign targeting Russian organizations. The malware uses multithreading and advanced tactics to stealthily collect data and maintain control over compromised systems. #TaxOff #TrinperBackdoor #OperationForumTroll #CVE2025-2783
Keypoints
- The attack exploited a sandbox escape vulnerability in Google Chrome, identified as CVE-2025-2783.
- TaxOff, a sophisticated hacking group, used phishing emails with malicious links to deliver the backdoor.
- The Trinper malware is written in C++ and capable of stealing host information, keystrokes, and files.
- Multiple attack campaigns, including one linked to October 2024, showed the groupβs use of loaders like Donut and Cobalt Strike.
- The group demonstrates extensive use of zero-day exploits and advanced malware to maintain long-term access.
Read More: https://thehackernews.com/2025/06/google-chrome-zero-day-cve-2025-2783.html