Kaspersky researchers identified a sophisticated cyber-espionage campaign, dubbed Operation ForumTroll, targeting organizations in Russia and Belarus. Attackers sent highly personalized phishing emails inviting recipients to the Primakov Readings forum, with links that, when clicked in Google Chrome or other Chromium-based browsers, exploited a zero-day vulnerability (CVE-2025-2783) to deliver malware. The campaign primarily targeted media outlets, universities, research centers, government organizations, and financial institutions, with the infection requiring no further user interaction beyond visiting the malicious site. The malware used in these attacks, initially named LeetAgent, communicated with its command server using obfuscated commands and was designed for espionage purposes.
Further investigation revealed that the tools and malware used in Operation ForumTroll were linked to the commercial spyware Dante, developed by the Italian company Memento Labs (formerly Hacking Team). The malware exhibited a modular structure, unique encryption keys per victim, and self-destruct capabilities. Analysis traced the use of Dante spyware in attacks dating back to 2022, indicating a broader campaign by the ForumTroll APT group and highlighting the continued evolution and deployment of commercial surveillance tools in targeted attacks against Russian and Belarusian entities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Kaspersky publicly disclosed detailed technical findings on Operation ForumTroll, LeetAgent, CVE-2025-2783 exploitation, and links to Dante, along with indicators of compromise. The report also warned that the pseudo-handle abuse behind CVE-2025-2783 may represent a broader class of vulnerabilities affecting other applications and Windows services.
By October 2025, Kaspersky concluded that Operation ForumTroll was likely connected to the broader toolset associated with Dante, a commercial spyware platform developed by Memento Labs, formerly Hacking Team. The attribution was based on deobfuscation results, code overlap, and shared tactics, even though Dante was not directly observed in the March infection wave.
After Kaspersky reported the issue, Google fixed the Chrome sandbox escape vulnerability CVE-2025-2783 in Chrome 134.0.6998.177/.178. The flaw abused a Windows pseudo-handle quirk during IPC handle relaying to obtain a real browser-process thread handle and execute shellcode.
The March 2025 ForumTroll campaign delivered the LeetAgent espionage implant to government, media, research, and private-sector targets in Russia and Belarus. The malware supported HTTPS command-and-control, keylogging, document theft, and follow-on tool downloads, with persistence established via COM hijacking.
In March 2025, attackers launched a spearphishing campaign using fake Primakov Readings forum invitations that led victims to short-lived malicious links. Simply visiting the link in Chrome or another Chromium-based browser triggered exploitation of a sandbox escape later tracked as CVE-2025-2783.
Kaspersky found related activity associated with the broader ForumTroll/Dante toolset dating back to 2022, affecting targets in Russia and Belarus. This earlier activity helped establish historical infrastructure, tooling, and TTP overlap later used for attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcesecurelist.com
Open sourcesecurityaffairs.com
Open sourcekaspersky.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.