logo

Operation ForumTrol Known for Exploiting Chrome 0-Day Attacking Users With New Phishing Campaign

ID: 8c35ef7c-97fc-5b4c-934b-d33f258848bd

STIX ID: report--8c35ef7c-97fc-5b4c-934b-d33f258848bd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Operation ForumTrol is a targeted APT phishing campaign (reported October 2025) that impersonates the eLibrary service to deliver personalized archive files which execute a PowerShell-based loader; the loader downloads a DLL, installs it at %localappdata%\Microsoft\Windows\Explorer\iconcache\_.dll, gains persistence via COM Hijacking (HKCR\CLSID...\InProcServer32), and deploys the Tuoni remote-access framework. The attackers used domain aging, cloned pages, device checks, and decoy files to evade detection while focusing on Russian political scientists and researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.