Dante is a modular commercial Windows spyware platform developed by Memento Labs, the successor to the Italian surveillance vendor Hacking Team. It has been linked to espionage activity targeting organizations and individuals in Russia and Belarus, including government bodies, media outlets, universities, research centers, and financial institutions. Kaspersky linked Dante-related incidents to the ForumTroll threat cluster and reported that the LeetAgent implant was at times used to launch Dante. Dante was not directly observed in ForumTroll's March 2025 Chrome zero-day intrusion chain, but malware, loader, and persistence overlaps connected it to related activity.
Dante uses an orchestrator component to manage encrypted modules, command-and-control communications, and self-protection. Its reported surveillance functions include keystroke logging, screenshot capture, file theft, data exfiltration, and remote command execution. Modules can be loaded from disk or memory and are encrypted with host-specific keying material. Dante employs VMProtect-based code and string obfuscation, indirect Windows API invocation, anti-debugging, virtual-machine and sandbox detection, and can remove itself if it does not receive commands for a configured period. Code lineage and design similarities link Dante to Hacking Team's Remote Control System, also known as Da Vinci.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Kaspersky’s technologies successfully identified a sophisticated zero-day exploit that was used to escape Google Chrome’s sandbox. After conducting a quick analysis, we reported the vulnerability to the Google security team, who fixed it as CVE-2025-2783.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While analyzing the malware used in these attacks, we discovered an unknown piece of malware that we identified as commercial spyware called “Dante” and developed by the Italian company Memento Labs (formerly Hacking Team).
Analyzing the old attacks, the researchers found "an unknown piece of malware that we identified as commercial spyware called “Dante” and developed by the Italian company Memento Labs."
20 distinct techniques documented for this family, organized by ATT&CK tactic.
No further action was required to initiate the infection; simply visiting the malicious website using Google Chrome or another Chromium-based web browser was enough.
Kaspersky said the malware infections occurred when victims clicked on personalized phishing links via email. It was disguised as an invitation from organizers of the scientific and expert forum for Primakov Readings, an international summit on global politics and economics.
First of all, the spyware is packed with VMProtect. It obfuscates control flow, hides imported functions, and adds anti-debugging checks. On top of that, almost every string is encrypted.
It also performs several anti-sandbox checks. It searches for “bad” libraries, measures the execution times of the sleep() function and the cpuid instruction, and checks the file system.
Notably, we saw several minor similarities between this attack and others involving Dante, such as similar file system paths, the same persistence mechanism, data hidden in font files, and other minor details.
The malware connects to one of its C2 servers specified in the configuration and uses HTTPS to receive and execute commands
Spent days trying to implement a multi-hop SOCKS5 proxy chain before I even had a working C2 ... What I tried: Dante proxies, 3proxy chains, multi-hop obfuscation, rotating IPs.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom spyware trojan used as the final payload in Operation ForumTroll, providing surveillance and data exfiltration (keylogging, screenshots, file theft) plus remote command execution; uses encrypted C2 traffic disguised as legitimate HTTPS.
Spyware developed by Memento Labs, used in cyber-espionage operations by ForumTroll group.
Spyware developed by Memento Labs, used for surveillance and data exfiltration in targeted attacks.
Commercially-developed spyware implant (attributed here to Memento Labs/former Hacking Team) used in Operation ForumTroll.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.