Operation ForumTroll: Chrome Zero-Day Attack Linked to Italian Spyware Maker Memento Labs

Listen to this Post

Featured Image

The Hidden Threat Behind a Forum Invitation

A shocking cybersecurity revelation has shaken the digital intelligence world. Earlier this year, a zero-day vulnerability in Google Chrome—exploited in a campaign known as Operation ForumTroll—was used to deliver a stealthy spyware package tied to the Italian surveillance vendor Memento Labs, the successor of the infamous Hacking Team.

The campaign, uncovered by Kaspersky in March, specifically targeted Russian organizations across media, academia, government, research, and finance sectors. Victims received official-looking invitations to the Primakov Readings Forum that contained a single malicious link. Simply clicking and loading the page in any Chromium-based browser was enough to compromise the system.

Kaspersky’s report confirmed that the attackers exploited a Chrome sandbox escape zero-day, CVE-2025-2783, enabling the silent delivery of malware. What began as a clever phishing ploy unraveled into a deeper story of espionage, commercial spyware, and the resurfacing of a notorious Italian cyber firm.

The Roots of the Operation

The spyware used in the attack chain, Kaspersky revealed, dates back to 2022. During their forensic analysis, researchers discovered connections to older, undisclosed cyber operations targeting organizations in Russia and Belarus. Buried deep within the digital artifacts was a mysterious payload identified as “Dante”, a commercial surveillance tool developed by Memento Labs.

Memento Labs itself emerged from the ashes of Hacking Team, a Milan-based spyware company that sold its Remote Control System (RCS) surveillance suite to law enforcement and intelligence agencies around the world. After the company’s infamous 2015 breach exposed its dealings with authoritarian regimes, Hacking Team’s credibility collapsed.

In 2019, it was acquired by InTheCyber Group, which integrated its technologies and personnel under a new banner—Memento Labs. Four years later, at the ISS World Middle East and Africa conference, the company quietly introduced its new spyware framework, Dante, a name that would resurface in the ForumTroll operation.

Anatomy of the Attack

The ForumTroll campaign began with carefully crafted phishing emails containing short-lived malicious links. A validator script filtered out unintended visitors to ensure that only specific, high-value targets were infected.

Upon exploitation of the CVE-2025-2783 zero-day, the attackers executed shellcode inside the browser’s process, installing a persistent loader to inject a malicious DLL. This DLL decrypted the core payload: LeetAgent, a sophisticated modular spyware with capabilities such as command execution, file manipulation, keystroke logging, and data theft.

What made LeetAgent unique was its signature use of “leetspeak” in its command syntax—a clue that helped researchers link it to earlier cyber operations. Kaspersky found evidence that LeetAgent was deployed as early as 2022, sometimes as a precursor for delivering Dante spyware.

The Dante malware was particularly advanced. It was modular, retrieving its components from a remote command-and-control (C2) server. To cover its tracks, Dante was programmed to self-destruct if it lost contact with its C2 server for several days, leaving no trace of its existence.

The Shadow of Hacking Team

The similarities between Dante and the Hacking Team’s old RCS malware were unmistakable. Kaspersky’s analysts expressed high confidence that Memento Labs had evolved directly from Hacking Team’s infrastructure and codebase.

However, there’s a twist. While Kaspersky linked the spyware to Memento Labs, the author of the Chrome sandbox escape zero-day exploit might not be the same group. The exploit could have originated from an independent actor, sold or traded to Memento Labs, or integrated into the campaign through a third-party broker.

Both Google and Mozilla have since patched the vulnerabilities. Chrome addressed CVE-2025-2783 in version 134.0.6998.178, released on March 26, while Mozilla fixed its related issue, CVE-2025-2857, in Firefox version 136.0.4.

When contacted by BleepingComputer, Memento Labs did not respond to requests for comment.

What Undercode Say:

The Operation ForumTroll case represents more than just another zero-day exploit. It exposes the intersecting worlds of commercial spyware and state-sponsored cyber espionage—two domains that are increasingly overlapping.

Memento Labs, through its Dante spyware, exemplifies how surveillance technologies are being privatized, rebranded, and resold under corporate fronts. Despite the 2015 scandal that publicly dismantled Hacking Team, the same technical DNA continues to thrive under a new identity.

From an analytical standpoint, the attack sophistication seen in ForumTroll is remarkable for three reasons:

Precision Targeting: The phishing campaign wasn’t broad or noisy. It was laser-focused on strategic Russian institutions—suggesting a geopolitical motive rather than financial gain.

Exploit Chaining: The use of a Chrome sandbox escape shows access to high-value exploits, either developed internally or acquired from private exploit brokers.

Stealth Engineering: Both LeetAgent and Dante were designed with longevity and evasion in mind—reflecting a professional, well-funded team rather than a rogue hacker group.

If Dante is indeed an evolved form of RCS, it signals that the spyware market never truly disappeared after Hacking Team’s fall—it merely changed form. Such tools now circulate quietly through intelligence networks, allowing nations and corporations to conduct deniable surveillance.

There’s also a disturbing trend at play. The commercialization of zero-days and the recycling of espionage infrastructure by private firms blur the line between legitimate cybersecurity research and covert offensive operations. Companies like Memento Labs operate in the grey zone, exploiting regulatory gaps that permit “lawful interception” tools to morph into weapons of digital intrusion.

For victims—researchers, journalists, and state-linked institutions—this means that no browser or patch cycle can guarantee safety when vulnerabilities are traded on the underground market faster than vendors can fix them.

Ultimately, ForumTroll serves as a reminder that the ghosts of past cyberweapons rarely die. They evolve, adapt, and return under new banners. And as long as the demand for espionage persists, the legacy of Hacking Team will continue to echo through the hidden corridors of cyberspace.

🔍 Fact Checker Results

✅ CVE-2025-2783 is a confirmed Chrome zero-day patched in March 2025.
✅ Kaspersky publicly attributed the spyware “Dante” to Memento Labs with high confidence.
❌ Memento Labs has not officially confirmed or denied involvement in the ForumTroll operation.

📊 Prediction

🧠 Cyber espionage will grow more privatized as old spyware firms rebrand under corporate entities.
💻 More zero-day exploits will be weaponized through commercial brokers rather than state labs.
🌍 The next big wave of attacks may target global NGOs and research networks, using similar lure-based social engineering.

The next “ForumTroll” won’t arrive as a crude phishing email—it will disguise itself as legitimate collaboration, delivered through trusted platforms. In the digital age, trust itself has become the most effective exploit.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon