#TAXHAUL

Malware/Tool

2023-04-11 • Security Update Mandiant Initial Results

TAXHAUL, also called TxRLoader, is Windows malware found on targeted systems during Mandiant's investigation of the 3CX intrusion attributed to UNC4736, a cluster assessed with high confidence to have a North Korean nexus. It reads shellcode from a hardware-profile-GUID-named .TxR.0.regtrans-ms file under C:\Windows\System32\config\TxR\, then uses Windows CryptUnprotectData to decrypt it with a host-specific key. This environmental binding means the content can be decrypted only on the compromised system and raises the cost of analysis. In the documented case, TAXHAUL loaded a complex downloader that Mandiant named COLDCAT.

Tagged Reports

« Back