Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports
ID: 419835b4-bb2b-5f22-9197-deb93c5c3f67
STIX ID: report--419835b4-bb2b-5f22-9197-deb93c5c3f67
Feed Name: Securelist by Kaspersky
Operation ForumTroll is an ongoing APT campaign targeting organizations and individuals in Russia and Belarus: spring 2025 activity exploited CVE-2025-2783 to deploy rare implants (LeetAgent, Dante), while an October 2025 phishing campaign used a fake e-library.wiki site and personalized archives to deliver a PowerShell downloader that installed an OLLVM-obfuscated DLL loader and the Tuoni remote access framework, using COM hijacking for persistence and fastly.net subdomains for C2; multiple indicators of compromise and TTPs are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
