Skip to main content
Mallory
MalwareUsed by 2 actorsExploits 1 CVE

Dante

Dante is a commercial Windows spyware platform developed by the Italian company Memento Labs, the rebranded successor to Hacking Team. Kaspersky identified it in attacks linked to the ForumTroll threat cluster and reported that it had been used in operations dating back to at least 2022, including targeting organizations and individuals in Russia and Belarus such as government bodies, media outlets, universities, research centers, and financial institutions. In reporting on Operation ForumTroll, Dante is described as a sophisticated surveillance implant associated with Memento Labs’ broader tooling alongside the LeetAgent backdoor; some reporting states LeetAgent was used to introduce or load Dante in related attacks, while Kaspersky also noted Dante was observed in other attacks linked to the same group rather than directly in the March 2025 Chrome zero-day campaign.

High-confidence capabilities described for Dante include keylogging, screenshot capture, file theft and broader data exfiltration, and remote command execution. It is modular: an orchestrator component decrypts and loads encrypted plug-in modules from disk or memory, and modules are stored locally encrypted, including AES/AES-256 protection tied to device-unique host information such as CPU identifier and Windows Product ID. Dante’s command-and-control communications are described as encrypted and disguised as legitimate HTTPS-like traffic. It also includes persistence mechanisms, with reporting noting overlap in persistence tradecraft with ForumTroll activity, including COM hijacking in related operations.

Dante is heavily engineered for evasion and anti-analysis. Reported protections include VMProtect-based code obfuscation, encrypted strings, indirect Windows API invocation to reduce detection, anti-debugging, anti-sandbox and anti-VM checks, and self-protection logic. Its orchestrator has been described as disguised as a font file, and data hidden in font files was noted as an overlap between Dante-related attacks and ForumTroll activity. Dante can self-delete if it does not receive commands after a defined period. Researchers also reported similarities between Dante and Hacking Team’s legacy RCS/Da Vinci spyware, including code overlap and a continued focus on stealth and modular surveillance functionality.

Associated intrusion activity described in the source material includes spear-phishing campaigns using personalized lures, including forged Primakov Readings invitations, and in broader ForumTroll operations exploitation of Google Chrome zero-day CVE-2025-2783 to compromise Windows systems. Reported indicators and traits include COM hijacking persistence, encrypted local modules, orchestrator components masquerading as font files, and detection opportunities based on a unique call stack signature referenced in detection content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-2783Google Chrome Mojo sandbox escape on WindowsExploited in the wild

Kaspersky researchers said that the malware delivery was done by exploiting CVE-2025-2783, a sandbox escape zero-day in the Chrome browser.

via bleeping computerbleepingcomputer.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Operation ForumTroll

While analyzing that malware, researchers found a previously undiscovered commercial spyware product Memento Labs developed known as “Dante,” according to Kaspersky.

via cyberscoopcyberscoop.com
Hacking Team

Analyzing the old attacks, the researchers found "an unknown piece of malware that we identified as commercial spyware called “Dante” and developed by the Italian company Memento Labs."

via bleeping computerbleepingcomputer.com
MITRE ATT&CK

Techniques & procedures

15 distinct techniques documented for this family, organized by ATT&CK tactic.

T1608.003Install Digital CertificateEvidence1

“After a successful breach, the malicious link automatically redirected users to the genuine forum website, effectively erasing traces of the attack…”

Initial Access

3 techniques
T1189Drive-by CompromiseEvidence2

No further action was required to initiate the infection; simply visiting the malicious website using Google Chrome or another Chromium-based web browser was enough.

T1566PhishingEvidence1

Kaspersky said the malware infections occurred when victims clicked on personalized phishing links via email. It was disguised as an invitation from organizers of the scientific and expert forum for Primakov Readings, an international summit on global politics and economics.

T1566.001Spearphishing AttachmentEvidence1

“The campaign began with a precision spear-phishing operation… forging an official conference invitation… The fake invitations were distributed via email… The embedded link directed victims to a cloned website…”

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence2
TacticExecution

The campaign exploited a zero-day (or previously unknown and unpatched) vulnerability in Google Chrome. Google patched the vulnerability after it was alerted, Kaspersky said.

T1611Escape to HostEvidence1

“This vulnerability enabled sandbox escape… The initial exploit was solely responsible for escaping the browser sandbox and gaining system privileges…”

Stealth

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

“advanced anti-analysis techniques, including virtual machine detection, sandbox environment awareness, and security software process inspection…”

T1056.001KeyloggingEvidence1

“custom spyware trojan named “Dante”… functions—such as keylogging…”

Discovery

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

“advanced anti-analysis techniques, including virtual machine detection, sandbox environment awareness, and security software process inspection…”

Collection

3 techniques
T1005Data from Local SystemEvidence1

“Dante… functions—such as… file theft…”

T1056.001KeyloggingEvidence1

“custom spyware trojan named “Dante”… functions—such as keylogging…”

T1113Screen CaptureEvidence1

“Dante… functions—such as… screenshot capture…”

T1001Data ObfuscationEvidence1

Notably, we saw several minor similarities between this attack and others involving Dante, such as similar file system paths, the same persistence mechanism, data hidden in font files, and other minor details.

T1071.001Web ProtocolsEvidence1

“Its communication traffic was heavily encrypted and disguised as legitimate HTTPS traffic to evade network-level detection.”

T1090ProxyEvidence1

Spent days trying to implement a multi-hop SOCKS5 proxy chain before I even had a working C2 ... What I tried: Dante proxies, 3proxy chains, multi-hop obfuscation, rotating IPs.

T1105Ingress Tool TransferEvidence2

The Memento Labs' product additionally enables users to install any software on the computer unnoticed. One description, for instance, mentions the software Dante, which probably is referring to a monitoring tool from Memento Labs.

T1568Dynamic ResolutionEvidence1

“the attackers employed short-lived domain techniques to conceal their real command-and-control (C&C) servers.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping15

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.