#ForumTroll
Kaspersky researchers love attribution.

securelist.com/forumtroll-a...
October 27, 2025 at 10:15 PM
Hacking Team, now Memento Labs, is still at it. Operation Forum Troll targeted media outlets, universities, research centers, government organizations, financial institutions, and other organizations in Russia. securelist.com/forumtroll-a...
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
securelist.com
October 27, 2025 at 7:16 PM
Memento Labs (formerly Hacking Team) ist wieder aktiv & seine Software wird gegen russische Ziele eingesetzt Betroffen sind Medienhäuser, Bildungseinrichtungen sowie Finanz- und Regierungsorganisationen. securelist.com/forumtroll-a...
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
securelist.com
October 27, 2025 at 7:45 AM
We have discovered a new Google Chrome 0-day that is being used in targeted attacks to deliver sophisticated spyware 🔥🔥🔥. It was just fixed as CVE-2025-2783 and we are revealing the first details about it and “Operation ForumTroll” securelist.com/operation-fo...
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain
Kaspersky GReAT experts discovered a complex APT attack on Russian organizations dubbed Operation ForumTroll, which exploits zero-day vulnerabilities in Google Chrome.
securelist.com
March 25, 2025 at 10:00 PM
Kaspersky Exposes Chrome Zero-Day RCE (CVE-2025-2783) Delivering Memento Labs Spyware in ForumTroll Campaign
Kaspersky Exposes Chrome Zero-Day RCE (CVE-2025-2783) Delivering Memento Labs Spyware in ForumTroll Campaign
Kaspersky found a Chrome zero-day (CVE-2025-2783) and sandbox bypass being exploited by Operation ForumTroll to deploy Memento Labs (Hacking Team) commercial Dante spyware against Russian targets.
securityonline.info
October 28, 2025 at 5:48 AM
A zero-day vulnerability in Google Chrome exploited in Operation ForumTroll earlier this year delivered malware linked to Italian spyware vendor Memento Labs, born after IntheCyber ​​Group acquired the infamous Hacking Team.
Italian spyware vendor linked to Chrome zero-day attacks
A zero-day vulnerability in Google Chrome exploited in Operation ForumTroll earlier this year delivered malware linked to Italian spyware vendor Memento Labs, born after IntheCyber ​​Group acquired the infamous Hacking Team.
www.bleepingcomputer.com
October 27, 2025 at 4:37 PM
Chrome's zero-day (CVE-2025-2783), exploited in a state-sponsored phishing campaign ("Operation ForumTroll") targeting journalists, is patched. Malicious links bypassed sandbox protections. Update your Chrome browser.#ChromeZeroDayPatch
March 26, 2025 at 2:04 PM
Mem3nt0 mori – The Hacking Team is back!

Source:
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
securelist.com
October 27, 2025 at 11:32 AM
I remember thinking when I wrote that code: Do I reject just -1, or a range of negative handles? I went with -1 because it felt less risky, and I didn't want to introduce random crashes from some undocumented edge-case.

Sorry, in retrospect I could have made it a stronger defense-in-depth check.
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
securelist.com
October 30, 2025 at 2:14 PM
Remember HackingTeam? They're back as Memento Labs. Their tools were used vs media, universities, government, financial institutions in Russia. Phishing + Chrome 0-day exploit. Just clicking a link was enough for full infection. Quite a disclosure. securelist.com/forumtroll-a...
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
securelist.com
October 27, 2025 at 6:46 PM
-Leak exposes APT35 bureaucracy
-Prince of Persia APT returns
-ForumTroll targets Russian scholars
-APT reports on Arcane Werewolf, BlueDelta, BlindEagle, LongNosedGoblin
-React2Shell is now used for ransomware
-FreeBSD and HPE RCEs
-New DMA attacks
-Fewer critical bugs in 2024
December 19, 2025 at 9:22 AM
Google Chrome was affected by CVE-2025-2783
Google Chrome was affected by CVE-2025-2783
CVE-2025-2783 is a zero-day vulnerability affecting Google Chrome, uncovered in a targeted cyber-espionage campaign known as Operation ForumTroll. This critical flaw has allowed attackers to bypass…
thecyberthrone.in
March 27, 2025 at 8:28 AM
www.cnews.ru/news/top/202... / Поможет зарячженная вода в 3х литровой банке. Чумак лечил так в 90е! :)
Россия под атакой. Итальянские разработчики напустили вирусы-шпионы на россиян и белорусов - CNews
Новое расследование специалистов «Лаборатории Касперского» выявило связь между операцией ForumTroll и деятельностью...
www.cnews.ru
November 1, 2025 at 1:54 PM
CVE-2025-2783: Kaspersky recently identified a Chromium sandbox bypass that allowed chaining with another unnamed exploit for RCE. The technical details have not been released yet, as this was spotted ITW as a 0-day by an alleged #APT at the time of Kaspersky's writing of the article.
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain
Kaspersky GReAT experts discovered a complex APT attack on Russian organizations dubbed Operation ForumTroll, which exploits zero-day vulnerabilities in Google Chrome.
securelist.com
March 26, 2025 at 3:16 AM
🚨 Chrome Zero-Day Alert: CVE-2025-2783 has been exploited!🚨

A critical flaw in Chrome’s Mojo component allowed attackers to bypass sandbox security via targeted phishing. Learn more about this exploit at:

basefortify.eu/posts/2025/0...

#Chrome #ZeroDay #Cybersecurity #forumtroll
March 26, 2025 at 9:29 AM
Kaspersky researchers said Memento Labs appears to be behind both the Operation ForumTroll malware and spyware, known as Dante. via @timstarks.bsky.social cyberscoop.com/hacking-team...
Hacking Team successor linked to malware campaign, new 'Dante' commercial spyware
Kaspersky researchers said Monday that they’ve unearthed a malware campaign they’re linking to the successor company of the infamous Italy-based surveillance tech firm Hacking Team, and at the same ti...
cyberscoop.com
October 27, 2025 at 5:02 PM
Kaspersky researchers said 🇮🇹Memento Labs - the successor company of Hacking Team - appears to be behind both the Operation ForumTroll malware and #spyware, known as Dante.

✍️ @timstarks.bsky.social

cyberscoop.com/hacking-team...
Hacking Team successor linked to malware campaign, new 'Dante' commercial spyware
Kaspersky researchers said Monday that they’ve unearthed a malware campaign they’re linking to the successor company of the infamous Italy-based surveillance tech firm Hacking Team, and at the same ti...
cyberscoop.com
October 28, 2025 at 9:27 PM
Mem3nt0 mori – The Hacking Team is back!
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
securelist.com
October 27, 2025 at 5:28 AM
🕵️ Operation ForumTroll: A sophisticated APT campaign targeting Russia & Belarus just exposed a link to Dante, a next-gen commercial spyware.
💠 Chrome zero-day (CVE-2025-2783)
💠 LeetAgent → Dante infection chain
💠 Private surveillance tech meets state-level espionage

#Cybersecurity #Dante #Spyware
October 27, 2025 at 12:41 PM
Update your Chrome, Brave, Opera, Edge... NOW!

Google pushed out a patch for just one flaw, scored as critical and confirmed actively exploited.

More details
beyondmachines.net/event_detail...
Google urgently patches actively exploited Chrome flaw - patch now!
A sophisticated cyberattack campaign named "Operation ForumTroll" exploits a critical Google Chrome zero-day vulnerability (CVE-2025-2783, CVSS 9.8) that bypasses Chrome's sandbox protection, targetin...
beyondmachines.net
March 26, 2025 at 11:07 AM
" In a blog post, Kaspersky called the campaign 'Operation ForumTroll,' and said victims were targeted with a phishing email inviting them to a Russian global political summit": Google fixes Chrome zero-day security flaw used in hacking campaign targeting journalists | TechCrunch
Google fixes Chrome zero-day security flaw used in hacking campaign targeting journalists | TechCrunch
Kaspersky attributed the hacks to an espionage campaign targeting journalists and employees at educational institutions.
buff.ly
March 27, 2025 at 4:30 PM
Mem3nt0 moriによる攻撃で積極的に悪用されているChromeゼロデイ

CVE-2025-2783として追跡されているGoogle Chromeの重大なゼロデイ脆弱性が、「Operation ForumTroll」と呼ばれる標的型スパイ活動キャンペーンの一環として実際に悪用されています。 Kasperskyの新たな調査によると、この攻撃はMem3nt0 mori(ForumTroll APTとも呼ばれる)というグループに関連付けられており、イタリアのスパイウェアベンダーMemento Labsによって開発されたツールが関与しているようです。 高度な攻撃チェーン…
Mem3nt0 moriによる攻撃で積極的に悪用されているChromeゼロデイ
CVE-2025-2783として追跡されているGoogle Chromeの重大なゼロデイ脆弱性が、「Operation ForumTroll」と呼ばれる標的型スパイ活動キャンペーンの一環として実際に悪用されています。 Kasperskyの新たな調査によると、この攻撃はMem3nt0 mori(ForumTroll APTとも呼ばれる)というグループに関連付けられており、イタリアのスパイウェアベンダーMemento Labsによって開発されたツールが関与しているようです。 高度な攻撃チェーン 悪用は2025年3月に始まり、被害者はPrimakov Readingsフォーラムへの招待を装った非常に個別化されたフィッシングメールを受け取りました。 短期間のみ有効な悪意あるリンクをクリックすると、追加のユーザー操作を必要とせずに即座に感染が発生しました。攻撃は主にロシアとベラルーシの組織、大学、研究機関、金融機関、政府機関を標的としていました。 Kasperskyの分析によると、攻撃者はChromeや他のChromium系ブラウザを侵害するためにサンドボックスエスケープのエクスプロイトを展開していました。 この脆弱性は、Windowsの擬似ハンドルの処理における論理的な見落としから生じており、攻撃者はChromeのブラウザプロセス内でコードを実行できました。 Googleはこの問題をバージョン134.0.6998.177/.178で迅速に修正しました。Firefoxの開発者も後に関連する問題を自社ブラウザで発見し、CVE-2025-2857として対応しました。 最新ブラウザのゼロデイ脆弱性についてさらに読む:Google、2025年4件目のChromeゼロデイに緊急パッチを発行 Memento Labsに関連するスパイ活動ツール 調査員は、Operation ForumTrollで使用された悪意あるツールキットを2022年のMem3nt0 moriによるキャンペーンにまで遡ることができました。 これらの攻撃ではLeetAgentと呼ばれるスパイウェアが展開され、以下の機能を持っています: シェルコードやコマンドのリモート実行 バックグラウンドでのキーロガー実行 .docx、.xlsx、.pdfなどの拡張子を持つファイルの窃取 さらに詳しい分析により、Memento Labs(旧Hacking Team)が開発した商用製品であるDanteという、より高度なスパイウェアプラットフォームの使用も明らかになりました。 Danteマルウェアは、Hacking Teamの旧Remote Control Systemsスイートから進化したもので、広範な解析回避技術と暗号化通信を備えています。 影響と業界の対応 Kasperskyの研究者は、Mem3nt0 moriがForumTrollキャンペーンでDanteベースのコンポーネントを活用したと結論付けており、これはこの商用スパイウェアが実際に確認された初めての事例となります。 「このエクスプロイトは、攻撃者が明らかに悪意のある、または禁止された行為を行うことなくGoogle Chromeのサンドボックス保護を回避できたため、本当に私たちを困惑させました」とチームは述べています。 「これはWindows OSのあまり知られていない特性による強力な論理的脆弱性が原因でした。」 この発見は、国家や商用監視ベンダーによる継続的なリスクを浮き彫りにしています。Kasperskyは、他のソフトウェアやWindowsサービスにも同様の擬似ハンドル脆弱性がないか、セキュリティ研究者に調査を促しています。 Chromeの新しいパッチはこの抜け穴を塞ぎましたが、この事例はスパイ活動者とグローバルなスパイウェア市場の間に根強い重なりがあることを示しており、商用監視ツールが標的型サイバー作戦で新たな命を吹き込まれ続けていることを改めて示しています。 画像クレジット:CryptoFX / Shutterstock.com 翻訳元:
blackhatnews.tokyo
October 28, 2025 at 4:03 PM