A critical zero-day vulnerability in Google Chrome and other Chromium-based browsers, tracked as CVE-2025-2783, was exploited in the wild as part of a sophisticated espionage campaign. Research from Kaspersky attributes the campaign, named "Operation ForumTroll," to the Mem3nt0 mori APT group (also tracked as ForumTroll APT and TaxOff). Starting in March 2025, the attackers used highly targeted spear-phishing emails to lure victims into clicking a malicious link, which triggered the exploit and led to the deployment of the LeetAgent spyware. The spyware is reportedly developed by the Italian vendor Memento Labs. The campaign primarily targeted government, financial, research, and educational institutions in Russia and Belarus.
"Operation ForumTroll" is a classic example of a state-sponsored or state-aligned espionage operation, characterized by its use of a zero-day exploit, custom malware, and highly targeted social engineering.
Attack Chain:
T1566.002 - Phishing: Spearphishing Link).T1211 - Exploitation for Client Execution).The campaign successfully compromised multiple organizations within strategic sectors in Russia and Belarus. The primary impact is espionage and the theft of sensitive government, financial, and scientific information. The use of a commercial spyware tool like LeetAgent highlights the growing and controversial market for offensive cyber capabilities, where private companies develop and sell powerful hacking tools to government clients.
cmd.exe or powershell.exe.
Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.