Memento Labs and Operation ForumTroll: A Spyware Saga of Cyber Espionage and Zero-Day Exploits
A zero-day vulnerability in Google Chrome, exploited in Operation ForumTroll, delivered malware linked to Italian spyware vendor Memento Labs. The campaign targeted Russian organizations with malicious links. Chrome fixed CVE-2025-2783, the sandbox escape zero-day, in version 134.0.6998.178, released on March 26.

Hot Take:
Just when you thought it was safe to open your email, Operation ForumTroll swoops in with a high-stakes game of malware tag, starring Google Chrome, Memento Labs, and a zero-day vulnerability that just won’t quit. It’s like a spy thriller, but with more coding and fewer explosions!
Key Points:
- Operation ForumTroll exploited a zero-day vulnerability in Google Chrome to target Russian organizations.
- The malware linked to Italian spyware vendor Memento Labs, born from the ashes of the infamous Hacking Team.
- Kaspersky researchers discovered the attack chain, involving phishing emails and a complex malware delivery system.
- The malware used includes the modular spyware LeetAgent and Dante, a creation of Memento Labs.
- Zero-day vulnerability CVE-2025-2783 was patched by Google and Mozilla in March 2025.
Already a member? Log in here
