forumtroll_apt
ForumTroll APT is a threat group tracked by Kaspersky and attributed to Operation ForumTroll, a cyber-espionage campaign discovered in 2025. According to the provided content, the group targeted government bodies, research centers, universities, and media organizations in Russia and Belarus. The campaign began in March 2025 and used highly personalized phishing emails disguised as invitations to the 'Primakov Readings' forum. The intrusion chain exploited the Google Chrome zero-day CVE-2025-2783 to bypass Chrome's sandbox and obtain full system control. The attackers used a validator on the malicious site to confirm real users before executing the attack, achieved persistence through Windows COM hijacking, and deployed the LeetAgent spyware to steal files, execute commands, and record keystrokes. Kaspersky identified operational and code links between LeetAgent and the Dante spyware platform. Dante is described in the content as a commercial surveillance tool developed by Memento Labs, formerly Hacking Team, and the content states that ForumTroll APT has used Dante since at least 2022. Known alias in the provided content: forumtroll_apt.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.