الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky spot new HackingTeam spyware in the wild after years of silence

Kaspersky Global Research and Analysis Team (GReAT) has uncovered evidence linking the HackingTeam successor, Memento Labs, to a new wave of cyberespionage attacks. The discovery stems from an investigation into Operation ForumTroll, an Advanced Persistent Threat (APT) campaign that exploited a zero-day vulnerability in Google Chrome. The research was presented at the Security Analyst Summit 2025, taking place in Thailand on October 26-29.

In March 2025, Kaspersky GReAT brought to light Operation ForumTroll, a sophisticated cyberespionage campaign exploiting a Chrome zero-day vulnerability, CVE-2025-2783. The APT group behind the attack sent personalized phishing emails disguised as invitations to the Primakov Readings forum, targeting Russian media outlets, educational institutions, and government organizations.

While investigating ForumTroll, researchers identified that the attackers used a spyware LeetAgent, which stood out due to its commands written in leetspeak, a rare feature in APT malware. Further analysis uncovered similarities between its toolset and a more advanced spyware that Kaspersky GReAT has observed in other attacks. After determining that, in some cases, the latter was launched by LeetAgent or that they shared a loader framework, researchers confirmed the connection between the two, as well as between the attacks.

Although the other spyware employed advanced anti-analysis techniques, including VMProtect obfuscation, Kaspersky retrieved the malware’s name from the code and identified it as Dante. The researchers discovered that a commercial spyware with the same name was promoted by Memento Labs, the rebranded successor to HackingTeam. Additionally, the most recent samples of HackingTeam’s Remote Control System spyware, obtained by Kaspersky GReAT, share similarities with Dante.

“While the existence of spyware vendors is well-known in the industry, their products remain elusive, particularly in targeted attacks where identification is exceptionally challenging. Uncovering Dante origin demanded peeling back layers of heavily obfuscated code, tracing a handful of rare fingerprints across years of malware evolution, and correlating them with a corporate lineage. Maybe it is the reason they called it Dante, there is a hell of a journey for anyone who would try to find its roots”, said Boris Larin, principal security researcher at Kaspersky GReAT.

The researchers traced the first use of LeetAgent back to 2022 and discovered additional attacks by ForumTroll APT targeting organizations and individuals in Russia and Belarus. The group stands out for its strong command of Russian and knowledge of local nuances, traits that Kaspersky observed in other campaigns linked to this APT threat. However, occasional errors suggest that the attackers were not native speakers.

The attack leveraging LeetAgent was first detected by Kaspersky Next XDR Expert. The full details of this research, as well as future updates on ForumTroll APT and Dante, are available to customers of the APT reporting service through Kaspersky Threat Intelligence Portal.
For more details and indicators of compromise, see the article on Securelist.com.

Related Posts:

Madinet Masr Awards EGP 1.38 Billion for Origami at Taj City

إدراج 47 جامعة مصرية في تصنيف UI GreenMetric للاستدامة لعام 2026

حجر أساس لمشروع أعلاف باستثمارات صينية.. والزراعة تؤكد دعم الشراكة مع القطاع الخاص

Zoho Launches Agent-Ready Catalyst Platform for AI App Development

Turkish Airlines Named Europe’s Best Airline for the 11th Time

NILEWOOD Expands in Saudi Arabia at Saudi Wood Show 2026

Turkish Airlines and Air China Expand Codeshare Agreement

PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion

آخر الأخبار
اورنچ مصر ووادي دجلة تطلقان منظومة حلول ذكية بــ«نيو» في مستقبل سيتي أورنچ مصر وهواوي تطلقان أول تجربة عالمية لتقنية CCIC على شبكات الميكروويف بنك saib يرفع العائد على شهادة Excellence الثلاثية إلى 18.25% كوربوريت ستاك تنفذ مشروعًا لرقمنة 1000 مصنع بالتعاون مع مركز تحديث الصناعة الذكاء الاصطناعي في الفصول الدراسية.. كيف يتخيل الجيل Z مستقبل التعليم؟ ڤاليو تنجح في إتمام إصدار سندات توريق بقيمة 945.8 مليون جنيه إم إن تي-حالاࣧ تنجح فى إتمام مجموعة من إصدارات سندات التوريق بقيمة تتجاوز 4 مليار جنيه بنهاية الربع ... تنميه تتعاون مع«ايسكور»و«سينابس أناليتكس»لتطوير قرارات الائتمان بالذكاء الرقمي مع هيونداي توسان.. راحة بالك تمتد لـ3 سنوات أو 60 ألف كيلومتر مع باقة الصيانة الخاصة من جي بي أوتو قمة الابتكار الجامعي 2026 تعلن الفرق الفائزة بمشاركة 100 مشروع من 30 جامعة سالي سلامة أمام الاختبار الأصعب في نيسان مصر.. هل تعود الثقة من بوابة العميل والأمان؟ محافظ البنك المركزي يبحث مع مسؤول «التمويل الدولية» تعزيز التعاون المشترك وزير الأوقاف يلتقي المشرفات من الواعظات عبر تقنية الاتصال المرئي لمتابعة العمل الدعوي مصر تدين اقتحام المستوطنين الإسرائيليين للمسجد الأقصى المبارك بنك القاهرة وشركة فيزا يوقعان اتفاقية تعاون لدعم تطوير حلول ومنتجات دفع جديدة محافظ البنك المركزي ووزير الصناعة يطلقان صندوق إعادة هيكلة المصانع المتعثرة برأسمال مليار جنيه إف سي بايرن ميونخ يؤسس أكاديمية تعمل على مدار العام في الشرق الأوسط، ويقدّم نموذجه المتميز لتطوير ال... دولة الإمارات تجدد التزامها بالتنمية المستدامة خلال الاجتماع السنوي لمجلس محافظي البنك الآسيوي للاس... المكتب الطبي يعلن حصول «مستشفيات الشيخ خليفة» على اعتماد «مسار التميّز بامتياز» من «المركز الأمريكي ... مجموعة دلسكو تطلق برنامج «خطوة» للمواهب الوطنية لتطوير وتمكين الكفاءات الإماراتية