Researchers at Kaspersky uncovered a sophisticated espionage campaign exploiting a zero-day vulnerability in Google Chrome and delivering commercial spyware linked to the Italian company Memento Labs β formerly known as Hacking Team.
Dubbed Operation ForumTroll, the campaign began with personalized phishing emails that invited recipients to the Primakov Readings, a well-known Russian scientific forum. Simply visiting the malicious website was enough to infect the victim. As Kaspersky explains, βNo further action was required to initiate the infection; simply visiting the malicious website using Google Chrome or another Chromium-based web browser was enough.β
The phishing emails were meticulously crafted and written in authentic Russian, targeting media outlets, universities, research centers, financial institutions, and government organizations across Russia. Each email contained a unique, short-lived phishing link designed to bypass detection.
According to Kaspersky, βThe malicious emails sent by the attackers were disguised as invitations from the organizers of the Primakov Readings scientific and expert forum. These emails contained personalized links to track infections.β
The campaignβs professionalism and language proficiency suggest regional expertise, though βmistakes in some cases suggest that the attackers were not native Russian speakers,β the report notes β a sign of deliberate masquerade.

Kasperskyβs investigation revealed a previously unknown Chrome zero-day (CVE-2025-2783) that allowed the attackers to escape Chromeβs sandbox using an obscure Windows API flaw.
The exploit abused pseudo-handles such as -2 returned by GetCurrentThread(), which were not properly validated by Chromeβs interprocess communication (IPC) mechanisms. This logical oversight enabled attackers to escalate privileges from a sandboxed renderer to the browser process.
As Kaspersky describes, βThis exploit genuinely puzzled us because it allowed attackers to bypass Google Chromeβs sandbox protection without performing any obviously malicious or prohibited actions. This was due to a powerful logical vulnerability caused by an obscure quirk in the Windows OS.β
The vulnerability has since been patched in Chrome 134.0.6998.177/.178, with the fix credited to Kaspersky. Interestingly, Mozilla later discovered a similar issue, releasing CVE-2025-2857 for Firefox.
Kaspersky notes, βWhen pseudo handles were first introduced, they simplified development and helped squeeze out extra performanceβ¦ Now, decades later, that outdated optimization has come back to bite us.β
After exploiting the browser, the attackers deployed a multi-stage loader chain beginning with a βvalidatorβ script that used the WebGPU API to verify human visitors. This validator performed elliptic-curve key exchange (ECDH) and decrypted the next payload hidden in fake JavaScript and font files.
Persistence was established using COM hijacking, a technique that overrides legitimate CLSID registry entries to execute malicious DLLs. The loader decrypted the final payload only when running within specific system processes, increasing stealth.
Kaspersky explains, βThe attackers used this technique to override the CLSID of twinapi.dll and cause system processes and web browsers to load the malicious DLL.β
The decrypted payload, named LeetAgent, acted as the spyware component of the campaign. Its command identifiers were humorously written in leetspeak β such as 0x6177 (KILL) and 0xF17E09 (FILE) β giving the malware its name.
LeetAgent executed remote commands, performed keylogging, and exfiltrated sensitive documents with extensions like .doc, .xls, .pdf, and .pptx. Communication with command-and-control (C2) servers occurred via HTTPS with obfuscation layers, often leveraging Fastlyβs CDN infrastructure.
In a major revelation, Kaspersky traced the campaignβs secondary payloads to Dante, a commercial spyware product developed by Memento Labs, the rebranded successor of Hacking Team.
The analysts wrote, βAfter analyzing this previously unknown, sophisticated spyware, we were able to identify it as commercial spyware called Dante, developed by the Italian company Memento Labs.β
Like Hacking Teamβs infamous Remote Control Systems (RCS) spyware, Dante is engineered for covert surveillance, featuring VMProtect packing, anti-debugging, anti-sandbox checks, and modular architecture. It decrypts its configuration data using XOR and AES-256-CBC, with the encryption key bound to the victim machineβs hardware ID.
Kaspersky points out, βWhy did the authors name it Dante? This may be a nod to tradition, as RCS spyware was also known as βDa Vinciβ. But it could also be a reference to Danteβs Divine Comedy, alluding to the many βcircles of hellβ that malware analysts must pass through when detecting and analyzing the spyware.β
Through overlapping infrastructure, persistence methods, and code similarities, Kaspersky linked LeetAgent and Dante to the same ForumTroll APT group. The company observed similar attacks dating back to 2022, primarily targeting entities in Russia and Belarus.
While the attackers demonstrated strong regional awareness, Kasperskyβs linguistic and infrastructure analysis suggests foreign actors using commercial spyware as part of a state-aligned or mercenary espionage operation.
Related Posts:
- Kaspersky Report: Criminals earning millions through mining malware
- New Agent Tesla Spyware Variant was spread via Microsoft Word documents
- Windows Sandbox Gets Supercharged: Clipboard and File Sharing Arrive
- Predators for Hire: A New Report Exposes the Thriving Global Spyware Industry
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.