Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor
A threat actor called TaxOff used a now-patched Google Chrome security hole as a zero-day attack to launch a backdoor nicknamed Trinper.
Positive Technologies discovered the attack in mid-March 2025, and it used a sandbox escape vulnerability known as CVE-2025-2783 (CVSS score: 8.3). Later that month, after Kaspersky revealed in-the-wild exploitation in an operation called Operation ForumTroll that targeted multiple Russian groups, Google fixed the vulnerability.
According to security specialists Vladislav Lunin and Stanislav Pyzhov, the first attack vector was a phishing email with a malicious link. The Trinper backdoor used by TaxOff was installed as a result of the user clicking the link, which set off a one-click exploit (CVE-2025-2783).
According to Kaspersky, the phishing e...

