Operation ForumTroll, an advanced persistent threat group, has launched a highly targeted phishing campaign against Russian political scientists and researchers at major universities and research institutions. The attackers impersonated the legitimate Russian scientific electronic library eLibrary, sending personalized phishing emails from the address support@e-library[.]wiki and prompting recipients to download supposed plagiarism reports. The malicious links led to ZIP archives named after the victims, containing malware such as the LeetAgent backdoor and Dante spyware, both previously associated with this group. The campaign demonstrates significant preparation, including registering the malicious domain six months in advance and cloning the legitimate eLibrary homepage to enhance credibility and evade detection.
The phishing campaign was first detected in October 2025 by Kaspersky and Securelist researchers, who noted that the attackers shifted their focus from organizations in the spring to individual scholars in the fall. The malicious domain was aged strategically to avoid spam filters, and the phishing links were designed for one-time use, complicating security analysis. The operation highlights the evolving tactics of Operation ForumTroll, which previously exploited the Google Chrome zero-day vulnerability CVE-2025-2783, and underscores the ongoing threat to academic and research communities in Russia from sophisticated, well-resourced threat actors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On December 17-18, 2025, multiple security outlets reported Kaspersky/Securelist findings on the newly identified ForumTroll operation targeting Russian scholars with fake eLibrary emails and plagiarism-themed lures. The reporting disclosed the campaign's targeting, delivery methods, and malware chain.
The campaign exploited Google Chrome zero-day CVE-2025-2783 to execute a PowerShell-based infection chain that downloaded DLL payloads, established persistence via COM hijacking, and deployed malware including LeetAgent, Dante, and the Tuoni C2 framework. The activity demonstrated a sophisticated espionage-oriented intrusion set focused on Russian academic targets.
The attackers sent tailored phishing emails impersonating eLibrary and fake plagiarism-report notifications to lure scholars into opening malicious files. Victims were directed to download personalized ZIP archives containing a malicious shortcut and decoy content.
In October 2025, researchers detected a new ForumTroll campaign aimed at Russian political science, international relations, and economics scholars at major universities and research institutions. The operation marked a shift from targeting organizations to targeting individual academics with highly personalized lures.
ForumTroll prepared the campaign by registering a lookalike eLibrary domain months before the attacks and cloning the service's homepage to support phishing and evade detection. The infrastructure was aged and configured with one-time-use links and other anti-analysis measures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.