Operation ForumTroll is a state-sponsored APT cyberespionage campaign targeting organizations in Russia, including entities in the education, finance, government, media, and research sectors. The campaign used phishing emails masquerading as forum invitations to deliver personalized, short-lived links to exploit sites. It exploited Chrome zero-day CVE-2025-2783, a sandbox escape vulnerability, and reporting also linked a similar Firefox flaw, CVE-2025-2857, to the broader activity. The attack chain validated users, bypassed the browser sandbox, executed shellcode to install a malware loader, and achieved persistence by hijacking the Windows search order for COM objects via registry entries. The final payload was LeetAgent spyware, which communicates over HTTPS and supports command execution, process launching, shellcode injection, keystroke logging, file theft, and file read/write operations. LeetAgent infrastructure was hosted on Fastly.net and has reportedly been used since at least 2022 in attacks in Russia and Belarus. Related reporting noted code similarities and shared persistence mechanisms with other attacks involving Dante spyware, developed by Memento Labs, formerly Hacking Team, although Dante was not directly used in Operation ForumTroll. Additional observed tradecraft included hiding data in font files.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.