Russian media, academia targeted in espionage campaign using Google Chrome zero-day exploit
ID: 90186c8f-7d05-5bf0-bc0e-614af974a024
STIX ID: report--90186c8f-7d05-5bf0-bc0e-614af974a024
Feed Name: The Record from Recorded Future News
Kaspersky identified a sophisticated espionage campaign named Operation ForumTroll that used phishing links exploiting a Chrome zero-day (CVE-2025-2783) to bypass the browser sandbox and infect targets (media and educational institutions) without additional user action; Google confirmed active exploitation and pushed a security update. The report also references related spyware (LianSpy) and earlier campaigns, and Kaspersky assesses the operation as likely state-sponsored.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
