logo

Russian media, academia targeted in espionage campaign using Google Chrome zero-day exploit

ID: 90186c8f-7d05-5bf0-bc0e-614af974a024

STIX ID: report--90186c8f-7d05-5bf0-bc0e-614af974a024

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-03-27

Date Updated: 2026-05-01

...
...

Kaspersky identified a sophisticated espionage campaign named Operation ForumTroll that used phishing links exploiting a Chrome zero-day (CVE-2025-2783) to bypass the browser sandbox and infect targets (media and educational institutions) without additional user action; Google confirmed active exploitation and pushed a security update. The report also references related spyware (LianSpy) and earlier campaigns, and Kaspersky assesses the operation as likely state-sponsored.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.