ForumTrol is an advanced persistent threat group associated with targeted phishing and post-compromise intrusion activity against Russian academic and research communities. The group has targeted individual political scientists, international relations specialists, and global economics researchers at major Russian universities and research institutions, indicating a focused interest in politically relevant scholarship and expert networks. ForumTrol has conducted highly personalized phishing operations that impersonate trusted academic services and use victim-specific lures. In 2025, the group used a campaign that exploited CVE-2025-2783 in Google Chrome and delivered malicious archives containing shortcut-based execution chains. The intrusion flow included PowerShell-based payload retrieval, deployment of an obfuscated loader, and installation of the Tuoni red teaming framework to provide remote access. The operation also used decoy documents to preserve the phishing pretext and incorporated technical checks to frustrate analysis and reduce exposure to non-target systems. The group has demonstrated persistence and defense-evasion tradecraft, including COM hijacking for persistence and anti-analysis measures on delivery infrastructure. ForumTrol has also previously deployed the LeetAgent backdoor and Dante spyware developed by Memento Labs. Reported activity shows a progression from targeting organizations to targeting individual scholars, reflecting careful reconnaissance and tailored victim selection. Overall, ForumTrol exhibits the hallmarks of a sophisticated espionage-oriented actor with strong phishing, malware delivery, persistence, and remote access capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.