Operation ForumTroll — APT Profile

Kaspersky's researchers dubbed this activity Operation ForumTroll after detecting a run of infections by previously unseen, high-end malware in mid-March 2025. Compromise took a single click: tailored, short-lived phishing links posing as invitations from the organisers of the "Primakov Readings" forum went to recipients at Russian media outlets, educational institutions and government organisations, and simply opening one in Chrome was enough, with no further action needed from the victim. The bug abused, CVE-2025-2783, was a sandbox escape that let the operators break out of Chrome's protective boundary; Google shipped a fix on 25 March 2025 and credited Kaspersky with the discovery. In October 2025 Kaspersky connected the group's implant LeetAgent, so named because its commands are written in leetspeak, to Dante, commercial spyware from the Italian vendor Memento Labs, the rebranded Hacking Team. The operators write convincing Russian and know local details, though mistakes in some of their other campaigns suggest they are not native speakers. A fresh wave that same October, disclosed in December 2025, swapped the payload for the commercial red-teaming framework Tuoni and baited political-science, international-relations and global-economics scholars at major Russian universities and research institutions with fake eLibrary plagiarism reports.

Also tracked as

Mem3nt0 mori, ForumTroll APT

IntelFusions coverage (1)

Tools & malware

Vendor research

Read the full analysis on IntelFusions