Kaspersky-labs · Crawled Jul 25, 2026

How we linked ForumTroll APT to Dante spyware by Memento Labs | Securelist

15 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

In March 2025, Kaspersky identified a sophisticated cyber espionage campaign dubbed Operation ForumTroll, targeting Russian and Belarusian organizations via spear phishing emails with personalized links. The attack exploited a zero-day vulnerability in Google Chrome (CVE-2025-2783) to escape the browser sandbox, leveraging a logical flaw in Windows IPC handling of pseudo-handles. The threat actor used LeetAgent, a custom spyware, and was linked to the commercial Dante spyware developed by Memento Labs (formerly Hacking Team), indicating a well-resourced and persistent threat actor conducting long-term surveillance operations.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 15 extracted

Type Value Detail
MD5 7d3a30dbf4fd3edaf4dde35ccb5cf926 Details →
SHA-1 3650c1ac97bd5674e1e3bfa9b26008644edacfed Details →
SHA-256 2e39800df1cafbebfa22b437744d80f1b38111b471fa3eb42f2214a5ac7e1f13 Details →
MD5 33bb0678af6011481845d7ce9643cedc Details →
SHA-1 8390e2ebdd0db5d1a950b2c9984a5f429805d48c Details →
SHA-256 388a8af43039f5f16a0673a6e342fa6ae2402e63ba7569d20d9ba4894dc0ba59 Details →
MD5 35869e8760928407d2789c7f115b7f83 Details →
SHA-1 c25275228c6da54cf578fa72c9f49697e5309694 Details →
SHA-256 07d272b607f082305ce7b1987bfa17dc967ab45c8cd89699bcdced34ea94e126 Details →
Filename Baltic_Vector_2023.iso Details →
Filename DRIVE.GOOGLE.COM Details →
Filename Invitation_Russia-Belarus_strong_partnership_2024.lnk Details →
Filename SCAN_XXXX_<DATE>.pdf.lnk Details →
Filename <DATE>_winscan_to_pdf.pdf.lnk Details →
Filename Rostelecom.pdf.lnk Details →

MITRE ATT&CK TTPs 20 techniques