الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky spot new HackingTeam spyware in the wild after years of silence

Kaspersky Global Research and Analysis Team (GReAT) has uncovered evidence linking the HackingTeam successor, Memento Labs, to a new wave of cyberespionage attacks. The discovery stems from an investigation into Operation ForumTroll, an Advanced Persistent Threat (APT) campaign that exploited a zero-day vulnerability in Google Chrome. The research was presented at the Security Analyst Summit 2025, taking place in Thailand on October 26-29.

In March 2025, Kaspersky GReAT brought to light Operation ForumTroll, a sophisticated cyberespionage campaign exploiting a Chrome zero-day vulnerability, CVE-2025-2783. The APT group behind the attack sent personalized phishing emails disguised as invitations to the Primakov Readings forum, targeting Russian media outlets, educational institutions, and government organizations.

While investigating ForumTroll, researchers identified that the attackers used a spyware LeetAgent, which stood out due to its commands written in leetspeak, a rare feature in APT malware. Further analysis uncovered similarities between its toolset and a more advanced spyware that Kaspersky GReAT has observed in other attacks. After determining that, in some cases, the latter was launched by LeetAgent or that they shared a loader framework, researchers confirmed the connection between the two, as well as between the attacks.

Although the other spyware employed advanced anti-analysis techniques, including VMProtect obfuscation, Kaspersky retrieved the malware’s name from the code and identified it as Dante. The researchers discovered that a commercial spyware with the same name was promoted by Memento Labs, the rebranded successor to HackingTeam. Additionally, the most recent samples of HackingTeam’s Remote Control System spyware, obtained by Kaspersky GReAT, share similarities with Dante.

“While the existence of spyware vendors is well-known in the industry, their products remain elusive, particularly in targeted attacks where identification is exceptionally challenging. Uncovering Dante origin demanded peeling back layers of heavily obfuscated code, tracing a handful of rare fingerprints across years of malware evolution, and correlating them with a corporate lineage. Maybe it is the reason they called it Dante, there is a hell of a journey for anyone who would try to find its roots”, said Boris Larin, principal security researcher at Kaspersky GReAT.

The researchers traced the first use of LeetAgent back to 2022 and discovered additional attacks by ForumTroll APT targeting organizations and individuals in Russia and Belarus. The group stands out for its strong command of Russian and knowledge of local nuances, traits that Kaspersky observed in other campaigns linked to this APT threat. However, occasional errors suggest that the attackers were not native speakers.

The attack leveraging LeetAgent was first detected by Kaspersky Next XDR Expert. The full details of this research, as well as future updates on ForumTroll APT and Dante, are available to customers of the APT reporting service through Kaspersky Threat Intelligence Portal.
For more details and indicators of compromise, see the article on Securelist.com.

Related Posts:

Dubai’s Commercial Property Market Surges to AED 30.38 Billion in Q3 2025, Marking a 31% Increase

UNITED HOSPITALITY MANAGEMENT APPOINTS MATTHIEU BUSSCHAERT AS GENERAL MANAGER OF CREEKSIDE HOTEL DUBAI BY ACCOR

New Digital Transformation for Services: Belda Platform Partners with Al Diwan Real Estate Development to Enhance Digital Transformation in the Services Market

STEP INTO THE MAGIC OF CHRISTMAS AT BATTERSEA POWER STATION

John Hewitt Joins Phygital International to Lead Worldwide Marketing & Communications

Domain Days Dubai 2025 sets new benchmark for global domain industry

Infracorp awards phase III construction contract of California Village project in Dubai to Abr Al Mutawassit Contracting Company

4th Digital Transformation Kuwait Conference to Advance Vision 2035 Through Innovation and Collaboration

آخر الأخبار
ﺗﯾﻠدا ﺗﻘدم ﺧدﻣﺔ Pay Apple ﻟﻌﻣﻼﺋﮭﺎ ﻓﻲ ﻣﺻر تعديلات سوق أبوظبي العالمي تعزز معايير المهن القانونية وترسخ بيئة الامتثال والشفافية بنك ABC يشارك في تحالف مصرفي لمنح تمويل مشترك بقيمة 4.485 مليار جنيه لصالح شركة مدكور للمشروعات بنك QNB مصر يقدم لعملائه خدمة Apple Pay ضمان تطلق سلسلة من المبادرات خلال شهر التوعية بسرطان الثدي شراكة استراتيجية جديدة لتعزيز الأمن الغذائي في دولة الإمارات الرئيس السيسى يلتقى رئيس صندوق تكريم شهداء ومصابى العمليات الحربية والإرهابية عماد ماهر: «نيو إيرا» تواصل مسيرتها بقوة بمشروعات متنوعة في مدينة "أكتوبر" منتجعات فورسيزونز المالديف تحتفي باليوم الوطني الإماراتي مع مجموعة من عروض الإقامة الحصرية من خلال شراكات في 6 مناطق بحرية للبحث عن الغاز .. قطر للطاقة تتوسع في مصر iCAUR تنظم قمة المستخدمين العالمية في الصين تحت شعار "التشارك في الإبداع والتعريف بالمستقبل" ايجكس تطلق أول منشأة لوجستية في السعودية متوافقة مع معايير ممارسات التصنيع الجيدة (GMP-GxP) لدعم قطا... وضع حجر أساس مشروعي "توب نيو للملابس الجاهزة" بالإسماعيلية "أبوظبي العقاري" يُبرم شراكة مع "الاتحاد للمعلومات الائتمانية" لتعزيز جاذبية الاستثمارات العقارية في... رئيس اقتصادية قناة السويس ونائب محافظ الإسماعيلية يشهدان وضع حجر أساس مشروعي "توب نيو للملابس الجاهز... مصر تعزز التعاون الإقليمي في مكافحة الجراد الصحراوي للحد من مخاطر انتشاره ومتابعة الوضع في دول التك... بيان من مجموعة الحبتور حول المساهمات في سوريا نيسان مصر توسع شبكتها عبر شراكة مع AMG Motors وافتتاح صالة عرض جديدة فى مدينة دمياط الجديدة معهد المبادرة وأكسنتشر يصدران تقريرًا رائدًا حول استثمارات الذكاء الاصطناعي في الأسواق الناشئة «الغرف العربية»: 7 تريليونات دولار حجم الاقتصاد الحلال عالميًا