Memento Labs and Operation ForumTroll: A Spyware Saga of Cyber Espionage and Zero-Day Exploits

A zero-day vulnerability in Google Chrome, exploited in Operation ForumTroll, delivered malware linked to Italian spyware vendor Memento Labs. The campaign targeted Russian organizations with malicious links. Chrome fixed CVE-2025-2783, the sandbox escape zero-day, in version 134.0.6998.178, released on March 26.

Pro Dashboard

Hot Take:

Just when you thought it was safe to open your email, Operation ForumTroll swoops in with a high-stakes game of malware tag, starring Google Chrome, Memento Labs, and a zero-day vulnerability that just won’t quit. It’s like a spy thriller, but with more coding and fewer explosions!

Key Points:

  • Operation ForumTroll exploited a zero-day vulnerability in Google Chrome to target Russian organizations.
  • The malware linked to Italian spyware vendor Memento Labs, born from the ashes of the infamous Hacking Team.
  • Kaspersky researchers discovered the attack chain, involving phishing emails and a complex malware delivery system.
  • The malware used includes the modular spyware LeetAgent and Dante, a creation of Memento Labs.
  • Zero-day vulnerability CVE-2025-2783 was patched by Google and Mozilla in March 2025.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?