Operation ForumTroll phishing and Chrome zero-day campaign against Russian organizations
Campaign
Summary
Hide ▲
Show ▼
Operation ForumTroll was exposed as a targeted phishing campaign that used a Google Chrome zero-day to compromise selected Russian organizations. The operation mattered because the lure pages delivered malware and enabled stealthy access through a browser exploit. Targeting spanned media outlets, universities, research centers, government organizations, and financial institutions. The campaign had already been active earlier this year and was uncovered in March.
Related Happenings
Gravity SMTP actively exploited information disclosure flaw (CVE-2026-4020)
Vulnerability
H score16
First: 19.06.2026 23:25
Last: 19.06.2026 23:25
Sources 1
About this happening:
An actively exploited unauthenticated information disclosure flaw in Gravity SMTP exposes API keys, secrets, OAuth tokens, and email-service credentials on sites using...
Gravity SMTP actively exploited information disclosure flaw (CVE-2026-4020)
VulnerabilityAbout this happening: An actively exploited unauthenticated information disclosure flaw in Gravity SMTP exposes API keys, secrets, OAuth tokens, and email-service credentials on sites using...
Microsoft SharePoint remote code execution (CVE-2026-45659)
Vulnerability
H score17
First: 26.05.2026 14:49
Last: 26.05.2026 14:49
Sources 1
About this happening:
Microsoft SharePoint CVE-2026-45659 is a remote code execution vulnerability that lets an authenticated attacker with Site Member permissions run code over the...
Microsoft SharePoint remote code execution (CVE-2026-45659)
VulnerabilityAbout this happening: Microsoft SharePoint CVE-2026-45659 is a remote code execution vulnerability that lets an authenticated attacker with Site Member permissions run code over the...
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
Campaign
H score33
First: 22.05.2026 14:30
Last: 22.05.2026 14:30
Sources 1
About this happening:
Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
CampaignAbout this happening: Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
Webworm expanded European government and South Africa university espionage campaign
Campaign
H score24
First: 20.05.2026 14:30
Last: 20.05.2026 14:30
Sources 1
About this happening:
Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
Webworm expanded European government and South Africa university espionage campaign
CampaignAbout this happening: Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...
MuddyWater broad cyber-espionage campaign across sectors and countries
Campaign
H score37
First: 14.05.2026 00:59
Last: 14.05.2026 00:59
Sources 1
About this happening:
MuddyWater was tied to a 2026 espionage campaign affecting at least nine organizations across nine countries on four continents, with victims in industrial a...
MuddyWater broad cyber-espionage campaign across sectors and countries
CampaignAbout this happening: MuddyWater was tied to a 2026 espionage campaign affecting at least nine organizations across nine countries on four continents, with victims in industrial a...
Timeline
-
17.12.2025 16:54 1 articles · 7mo ago
Operation ForumTroll targets Russian scholars with fake eLibrary emails
Campaign Scope UpdateKaspersky reported on December 17, 2025 that it detected a new Operation ForumTroll phishing wave in October 2025 targeting Russian scholars and researchers in political science, international relations, and global economics at major Russian universities and research institutions. The attackers used fake eLibrary emails from support@e-library[.]wiki, hosted a copy of elibrary[.]ru on e-library[.]wiki, and personalized ZIP archives named <LastName>_<FirstName>_<Patronymic>.zip for the targeted individuals.
Show sources
- New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails — thehackernews.com — 17.12.2025 16:54
-
27.10.2025 18:37 1 articles · 8mo ago
Kaspersky details Operation ForumTroll exploit chain and Memento Labs link
Technical Analysis UpdateKaspersky detailed Operation ForumTroll against Russian organizations, saying a phishing email with personalized, short-lived links led targets to a malicious site where a validator script filtered visitors, CVE-2025-2783 in Chromium-based browsers enabled shellcode execution and a persistent loader, and the DLL decrypted LeetAgent; the same analysis linked older attacks in Russia and Belarus to Dante and attributed the spyware to Memento Labs with high confidence, while also noting Chrome 134.0.6998.178 and Firefox 136.0.4 had already fixed the related browser flaws.
Show sources
- Italian spyware vendor linked to Chrome zero-day attacks — www.bleepingcomputer.com — 27.10.2025 18:37