Skip to main content
Mallory
3 malware familiesExploits CVEs in the wild

Team46

Also known asTaxOffteam46

TaxOff, also tracked as Team46, is a threat actor assessed in the provided content as a single adversary cluster operating under both names. The group has targeted Russian organizations, including domestic government agencies and other Russian entities, through phishing-led intrusions. Reported lures included invitations to the Primakov Readings forum, the “Security of the Union State in the modern world” conference, and Rostelecom-themed maintenance notices. The actor is linked to exploitation of Google Chrome zero-day CVE-2025-2783 in March 2025 to deploy the Trinper backdoor. The campaign, referred to in the content as Operation ForumTroll, used phishing emails with links to fake websites hosting the exploit, enabling a Chrome sandbox escape and installation of Trinper, in some reporting without further user interaction beyond the initial click. The content also links Team46/TaxOff to earlier activity involving a Yandex Browser DLL hijacking zero-day, CVE-2024-6473. Tradecraft described in the content includes phishing emails containing malicious links or ZIP archives with LNK files, PowerShell download-and-execute chains, use of decoy PDF documents, retrieval of payloads with the victim computer name passed as a query parameter, distinct User-Agent selection for decoy versus payload downloads, and DLL hijacking. In one October 2024 chain, the actor used rdpclip.exe with a replaced winsta.dll to load Trinper. The content also states the actor has used loaders such as Donut and Cobalt Strike. Trinper is described in the content as a C++ multithreaded backdoor associated with TaxOff. Reported capabilities include keystroke logging, host information collection, theft of targeted files including documents, command execution, reverse shell access, file read/write operations, directory changes, and self-termination. One reported C2 for Trinper was common-rdp-front.global.ssl.fastly.net. The group was first documented in late 2024, according to the content, and is described as using legal, finance-themed, and geopolitical phishing themes. Positive Technologies is cited as finding evidence linking TaxOff and Team46, and multiple excerpts state that Team46 and TaxOff represent the same activity cluster or a single adversary.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.