A threat actor called TaxOff used a now-patched Google Chrome security hole as a zero-day attack to launch a backdoor nicknamed Trinper.
Positive Technologies discovered the attack in mid-March 2025, and it used a sandbox escape vulnerability known as CVE-2025-2783 (CVSS score: 8.3). Later that month, after Kaspersky revealed in-the-wild exploitation in an operation called Operation ForumTroll that targeted multiple Russian groups, Google fixed the vulnerability.
According to security specialists Vladislav Lunin and Stanislav Pyzhov, the first attack vector was a phishing email with a malicious link. The Trinper backdoor used by TaxOff was installed as a result of the user clicking the link, which set off a one-click exploit (CVE-2025-2783).
According to Kaspersky, the phishing email tricked users into clicking on a link that sent them to a phony website that hosted the attack by read more about Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
