Operation ForumTroll — APT Profile
Kaspersky's researchers dubbed this activity Operation ForumTroll after detecting a run of infections by previously unseen, high-end malware in mid-March 2025. Compromise took a single click: tailored, short-lived phishing links posing as invitations from the organisers of the "Primakov Readings" forum went to recipients at Russian media outlets, educational institutions and government organisations, and simply opening one in Chrome was enough, with no further action needed from the victim. The bug abused, CVE-2025-2783, was a sandbox escape that let the operators break out of Chrome's protective boundary; Google shipped a fix on 25 March 2025 and credited Kaspersky with the discovery. In October 2025 Kaspersky connected the group's implant LeetAgent, so named because its commands are written in leetspeak, to Dante, commercial spyware from the Italian vendor Memento Labs, the rebranded Hacking Team. The operators write convincing Russian and know local details, though mistakes in some of their other campaigns suggest they are not native speakers. A fresh wave that same October, disclosed in December 2025, swapped the payload for the commercial red-teaming framework Tuoni and baited political-science, international-relations and global-economics scholars at major Russian universities and research institutions with fake eLibrary plagiarism reports.Also tracked as
Mem3nt0 mori, ForumTroll APT
IntelFusions coverage (1)
- Google Patches Two Chrome Zero-Days Exploited in the Wild — Skia and V8 Under Active Attack 2026-03-15 · Vulnerabilities
Tools & malware
- CVE-2025-2783 Chrome sandbox escape exploit exploit
- Dante commercial spyware
- LeetAgent backdoor
- Tuoni red-teaming framework
Vendor research
- Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain Kaspersky (Securelist)
- Mem3nt0 mori – The Hacking Team is back! Kaspersky (Securelist)
- A new campaign by the ForumTroll APT group Kaspersky (Securelist)
- Kaspersky GReAT identifies new ForumTroll campaign targeting Russian political scientists Kaspersky