#TAXHAUL
Malware/Tool
2023-04-11 • Security Update Mandiant Initial Results
TAXHAUL, also called TxRLoader, is Windows malware found on targeted systems during Mandiant's investigation of the 3CX intrusion attributed to UNC4736, a cluster assessed with high confidence to have a North Korean nexus. It reads shellcode from a hardware-profile-GUID-named .TxR.0.regtrans-ms file under C:\Windows\System32\config\TxR\, then uses Windows CryptUnprotectData to decrypt it with a host-specific key. This environmental binding means the content can be decrypted only on the compromised system and raises the cost of analysis. In the documented case, TAXHAUL loaded a complex downloader that Mandiant named COLDCAT.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days