Operation ForumTroll
0 incidentes
0 paises
0 sectores
apt UNKNOWN Ultimo: -
Aliases: taxoff, team46
Operation ForumTroll is a state-sponsored cyber espionage campaign that emerged by at least 2022, focusing on intelligence gathering. It is characterized by its highly targeted spear-phishing tactics using personalized lures, such as fake invitations to the 'Primakov Readings' forum or bogus plagiarism reports from eLibrary.ru, to exploit zero-day browser vulnerabilities like CVE-2025-2783 in Google Chrome. While the group's specific national origin remains unknown, its technical sophistication strongly suggests state sponsorship. A distinguishing characteristic is its confirmed association with Memento Labs, the successor to Hacking Team, and the use of their commercial spyware Dante. The group has also been referred to as Mem3nt0 mori or ForumTroll APT.