logo

Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain

ID: 4b3bb80f-ad42-5b34-830b-4054716581c8

STIX ID: report--4b3bb80f-ad42-5b34-830b-4054716581c8

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2025-03-25

Date Updated: 2026-04-29

Author: Igor Kuznetsov, Boris Larin

...
...

Kaspersky detected a targeted phishing campaign called Operation ForumTroll that used personalized, short-lived links exploiting a zero-day Chrome sandbox escape (CVE-2025-2783) to deliver sophisticated espionage malware to media, educational and government entities in Russia; Kaspersky reported the flaw to Google, which issued a patch on 2025-03-25, and provided detections and an IoC (primakovreadings.info).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.