ForumTroll is a cyber-espionage threat cluster active since at least 2022 and primarily associated with operations targeting organizations and individuals in Russia and Belarus. The group has been linked to campaigns against government bodies, media outlets, universities, research institutions, political experts, scholars, and financial organizations, indicating an intelligence-collection mission focused on politically relevant, academic, governmental, and institutional targets. ForumTroll is known for highly tailored spear-phishing and social-engineering operations. Reported lures have included invitations to prominent policy forums and fake plagiarism-related or academic-themed messages crafted for scholars and researchers. The group has used personalized, short-lived phishing links and victim-specific delivery mechanisms to reduce detection and increase targeting precision. In multiple campaigns, ForumTroll demonstrated strong familiarity with Russian-language and local contextual themes, although some reporting noted linguistic mistakes suggesting the operators may not be native Russian speakers. The actor has been associated with sophisticated exploitation, including use of the Google Chrome zero-day CVE-2025-2783 to escape the browser sandbox and facilitate compromise through a malicious website with minimal user interaction. ForumTroll operations have also used staged delivery chains, browser-side validation logic, encrypted payload retrieval, PowerShell-based execution, and persistence via COM hijacking. These tradecraft elements indicate a mature capability set spanning phishing, exploit deployment, stealthy malware loading, and post-compromise persistence. Malware linked to ForumTroll includes LeetAgent, a backdoor and spyware platform used for command execution, process launching, shellcode injection, keylogging, and theft of documents and other files. LeetAgent has also reportedly functioned as a loader for additional tooling. Related reporting further links ForumTroll-associated activity to use of Dante, a more advanced commercial spyware platform attributed to the Italian surveillance vendor Memento Labs, the successor to Hacking Team. Although Dante was not directly observed in every ForumTroll campaign, code, loader, and operational overlaps have been reported between ForumTroll-linked intrusions, LeetAgent, and Dante deployments. Some reporting also associates ForumTroll-linked campaigns with deployment of the Tuoni command-and-control and red-teaming framework in later academic-targeting operations. Across observed activity, the group’s objective is consistently assessed as espionage rather than disruption or financially motivated crime. Known aliases include forumtroll, forum_troll_apt, forumtroll_apt, and forumtroll_apt_group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeting Russian and Belarusian academics and experts with spear-phishing, zero-days, and spyware for espionage.
Forum Troll APT is conducting attacks targeting academic scholars by hijacking their systems through fake plagiarism reports.
ForumTroll is conducting sophisticated phishing campaigns targeting individuals in Russia, particularly scholars in political science, international relations, and global economics at major universities and research institutions. The campaigns use personalized phishing emails, exploit zero-day vulnerabilities, and deploy custom malware for espionage.
ForumTroll conducted Operation ForumTroll, a cyber espionage campaign using spear-phishing emails and a zero-day vulnerability in the Chrome browser to target government agencies, media, universities, research institutions, and financial institutions in Russia and other countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.