Two sides of the same coin
Essential information
- Published
- 18/04/2025 21:45
- Modified
- 21/04/2025 12:45
- Tags
- 2025-04-18 CVE-2024-6473 CVE-2025-2783 apt backdoor cobalt strike dante encryption loader obfuscation powershell trinper zero-day
- Related entities
- 1 intrusion sets (apt), 12 techniques (mitre), 3 malware
Description
This intelligence report analyzes the similarities between two previously separate APT groups, Team46 and TaxOff, concluding they are likely the same entity. The analysis covers their shared tactics, techniques, and procedures, including similar PowerShell commands, loader functionality, and infrastructure patterns. Key findings include the use of zero-day exploits, complex malware development, and long-term persistence strategies. The report details the groups' use of multi-layered encryption in their loaders, custom obfuscation techniques, and various malware tools like Trinper backdoor and Cobalt Strike. The combined group, now referred to as Team46, demonstrates sophisticated capabilities in targeted attacks against protected infrastructures.