Operation ForumTroll — APT Profile
Operation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Google Chrome, identified as CVE-2025-2783, which allowed attackers to bypass the browser's security features. Victims were infected by clicking on personalized phishing links in emails, allegedly from the organizers of the "Primakov Readings" forum, targeting media outlets, educational institutions, and government organizations in Russia. The goal of the attack appears to be espionage, and the campaign is believed to be the work of a state-sponsored APT group. Google quickly released an update to fix the vulnerability after being notified by Kaspersky.Also tracked as
Mem3nt0 mori, ForumTroll APT
IntelFusions coverage (1)
- Google Patches Two Chrome Zero-Days Exploited in the Wild — Skia and V8 Under Active Attack 2026-03-15 · Vulnerabilities
Tools & malware
- CVE-2025-2783 Chrome sandbox escape exploit exploit
- Dante commercial spyware
- LeetAgent backdoor
- Tuoni red-teaming framework
Vendor research
- Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain Kaspersky (Securelist)
- Mem3nt0 mori – The Hacking Team is back! Kaspersky (Securelist)
- A new campaign by the ForumTroll APT group Kaspersky (Securelist)
- Kaspersky GReAT identifies new ForumTroll campaign targeting Russian political scientists Kaspersky