ZeroHour
The Recordpublished ()ingested

Italian-made spyware spotted in breaches of Russian, Belarusian systems

criticalMalwareimportance 60CVE-2025-2783

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-2783
Sandbox Escape via Mojo Handle Flaw in Google Chrome on Windows (CVE-2025-2783)

CVE-2025-2783 is a high-severity sandbox escape in Google Chrome on Windows, caused by an incorrect handle being provided in unspecified circumstances in Mojo, Chrome's inter-process communication layer. It is triggered remotely through a malicious file and requires user interaction; an attacker who has code running inside Chrome's sandboxed renderer can abuse the handle flaw to break out of the Windows sandbox and gain broader access to the host (CVSS scope change with high impact to confidentiality, integrity, and availability). All Google Chrome versions on Windows prior to 134.0.6998.177 are affected, per the vendor fix referenced by CISA. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-27, and related reporting links it to active exploitation in the ForumTroll APT's phishing campaign against Russian scholars using fake eLibrary emails; ransomware use is unknown. No public proof-of-concept is known, and EPSS assigns a 9.2% probability of exploitation within 30 days (95th percentile).

Do: Update Google Chrome on Windows to 134.0.6998.177 or later immediately and verify deployed browser versions across endpoints; the flaw is in the CISA KEV catalog, so federal agencies must apply vendor mitigations per BOD 22-01 timelines. Because exploitation is tied to malicious files delivered via phishing (e.g., the ForumTroll fake-eLibrary campaign), prioritize patching for users who open untrusted attachments and links, and hunt for associated phishing emails.

8.39% KEV
  • Google Chrome Windows versions prior to 134.0.6998.177
  • Google Chromium (Mojo IPC component) Windows builds prior to the 134.0.6998.177 fix, as listed by CISA (affected component: Google Chromium Mojo)
massbillions of users (Chrome is the world's dominant browser; the Windows-only subset is still likely well over 1 billion)
Full article500 words · extracted from therecord.media · click to collapse

A Russian cybersecurity firm said it has found evidence that spyware developed by Italy’s Memento Labs — formerly known as the controversial Hacking Team — was likely used in attacks on organizations in Russia and Belarus.

In a report published Monday, researchers at Kaspersky said they identified the company’s commercial spyware, known as Dante, in multiple attacks linked to a hacking group dubbed ForumTroll.

Kaspersky said there is no evidence of active Dante infections among its customers, and researchers could not determine who commissioned ForumTroll’s operations. It is also unclear how much the attackers might have paid to use the spyware or whether the company was aware of its deployment, the report said.

“Proficiency in Russian and familiarity with local peculiarities are distinctive features of the ForumTroll group, traits that we have also observed in its other campaigns,” the researchers said. “However, mistakes in some of those other cases suggest that the attackers were not native Russian speakers.”

Milan-based Memento Labs did not respond to requests for comment.

The report marks the first documented instance of Dante’s use in real-world cyberattacks since it was unveiled by Memento Labs in 2023 during a closed conference for law enforcement and intelligence agencies, according to researchers.

Kaspersky’s discovery was the byproduct of an investigation into ForumTroll espionage attack in March of this year. The hackers targeted Russian media outlets, universities, research centers, government institutions, and financial organizations with phishing emails disguised as invitations to a well-known Russian scientific and expert forum. 

The attackers sent malicious links that exploited a zero-day vulnerability in Google’s Chrome browser, the researchers said. Kaspersky reported the bug, now tracked as CVE-2025-2783, and Google patched it.

Dante was not used in that campaign, the researchers said, but investigating ForumTroll incidents eventually led Kaspersky to discover the spyware elsewhere.

The most recent ForumTroll campaign included the group’s custom tool, LeetAgent, the researchers said. 

At times, it served as a loader for Dante, which is far more advanced, they said. LeetAgent dates back to at least 2022.

Hacking Team sold intrusion and surveillance tools to government clients worldwide before suffering a massive data leak in 2015. 

The firm was criticized for selling its Remote Control Systems (RCS) spyware to countries with “ongoing serious human rights violations,” according to a report by the digital rights watchdog Citizen Lab. In a 2014 report, Citizen Lab found that RCS was used by at least 20 countries, including Saudi Arabia, Sudan, Mexico, Azerbaijan, Egypt, Hungary, Italy and Kazakhstan.

After the leak, the company was acquired and rebranded as Memento Labs, and it has continued marketing its “intelligence solutions” to law enforcement and intelligence agencies.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/memento-labs-formerly-hacking-team-dante-spyware-russia-kaspersky