ForumTroll is a cyber-espionage threat cluster active since at least 2022 and known for targeting organizations and individuals in Russia and Belarus. The group has been associated with highly tailored spear-phishing campaigns using topical social-engineering lures, including fake invitations to the Primakov Readings forum and fraudulent plagiarism-report themes aimed at scholars and political experts. Victimology includes government bodies, media outlets, universities, research institutions, financial organizations, and individual academics, particularly in political science, international relations, and economics. ForumTroll is notable for combining precise targeting with advanced exploitation. In 2025 it was linked to Operation ForumTroll, a campaign that used personalized, short-lived phishing links and a malicious website to exploit Google Chrome sandbox-escape vulnerability CVE-2025-2783 against Chromium-based browsers. The intrusion chain included victim validation logic, staged payload delivery, and post-compromise malware deployment. Persistence has been achieved through COM hijacking, and the group has used loaders and implants designed to activate selectively and evade analysis. The principal malware associated with ForumTroll is LeetAgent, a spyware backdoor supporting remote command execution, process execution, task management, file operations, shellcode injection, configuration changes, keylogging, and theft of documents. ForumTroll-linked activity has also been connected to Dante, a more advanced commercial spyware platform attributed to the Italian surveillance vendor Memento Labs, the successor to Hacking Team. LeetAgent has at times been used as a loader for Dante, and technical overlaps have been reported among ForumTroll exploit code, loaders, and Dante-related tooling. Later activity also delivered the Tuoni command-and-control and red-teaming framework. The actor’s tradecraft includes spear-phishing, browser exploitation, selective payload staging, persistence, credential-adjacent surveillance through keylogging, and document exfiltration. The campaigns are assessed as espionage-focused. Although the operators have demonstrated strong familiarity with Russian-language and local contextual themes, publicly available reporting does not establish the actor’s own national origin with high confidence. Known aliases include Forum Troll APT, forum_troll_apt, forumtroll_apt, and forumtroll_apt_group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeting Russian and Belarusian academics and experts with spear-phishing, zero-days, and spyware for espionage.
Forum Troll APT is conducting attacks targeting academic scholars by hijacking their systems through fake plagiarism reports.
ForumTroll is conducting sophisticated phishing campaigns targeting individuals in Russia, particularly scholars in political science, international relations, and global economics at major universities and research institutions. The campaigns use personalized phishing emails, exploit zero-day vulnerabilities, and deploy custom malware for espionage.
ForumTroll conducted Operation ForumTroll, a cyber espionage campaign using spear-phishing emails and a zero-day vulnerability in the Chrome browser to target government agencies, media, universities, research institutions, and financial institutions in Russia and other countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.