Skip to main content
Mallory
MalwareUsed by 1 actorExploits 2 CVEs

Trinper

Trinper is a backdoor associated with the TaxOff threat actor, with reporting also linking TaxOff and Team46 as likely the same activity cluster. It was deployed in campaigns targeting Russian organizations, including government and critical infrastructure entities, and was observed in attacks from at least October 2024 through March 2025. A prominent delivery chain used phishing emails themed as invitations to high-profile events such as the Primakov Readings forum, leading victims to malicious sites that exploited the Google Chrome zero-day CVE-2025-2783 to install Trinper without further user interaction. Earlier campaigns also used ZIP/LNK-to-PowerShell infection chains and DLL hijacking, including abuse of rdpclip.exe by replacing winsta.dll, which served as a loader for the Trinper backdoor. Trinper is described as a multithreaded C++ backdoor capable of capturing host information, logging keystrokes, collecting targeted files including .doc, .xls, .ppt, .rtf, and .pdf, and communicating with a command-and-control server for tasking. Reported operator commands include reading and writing files, executing commands, launching a reverse shell, changing directories, extending capabilities, and self-termination. Open-source loaders such as Donut and Cobalt Strike were also reported in related intrusion chains. A reported C2 associated with Trinper is common-rdp-front.global.ssl.fastly.net.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2025-2783Google Chrome Mojo sandbox escape on WindowsExploited in the wild

A recently-patched Google Chrome flaw was exploited in March by a threat actor known as TaxOff... exploited a sandbox escape flaw (CVE-2025-2783) to bypass Chrome’s defenses... | A recently-patched Google Chrome flaw was exploited in March by a threat actor known as TaxOff, who used it to slip a stealthy backdoor called “Trinper” onto targeted systems.

via sentinelone blogsentinelone.com
CVE-2024-6473DLL Hijacking in Yandex Browser for Desktop

"A Chrome zero-day (CVE-2025-2783) got some action in March when a threat actor named TaxOff used it to drop their Trinper backdoor."

via vulnuvulnu.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Team46

...launched by the Team46 advanced persistent threat operation, also known as TaxOff, to spread the Trinper malware... allow subsequent Trinper backdoor installation without any user interaction...

via scworldscworld.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.