Tuesday, September 1, 2026

ForumTrol Operation Uses Chrome Zero-Day in Fresh Phishing Attacks

The ForumTroll APT group has resurfaced with a sophisticated phishing campaign targeting Russian academics, marking a significant escalation in their ongoing operations against entities in Russia and Belarus.

While the group initially gained notoriety for exploiting CVE-2025-2783, a zero-day vulnerability in Google Chrome, their latest offensive relies on refined social engineering tactics and commercial red teaming frameworks to compromise high-value targets.

Kaspersky GReAT researchers discovered the new campaign in October 2025, mere days before presenting their findings at the Security Analyst Summit.

The phishing emails impersonated eLibrary, a legitimate scientific electronic library widely used by Russian academics, targeting scholars specializing in political science, international relations, and global economics at major Russian universities and research institutions.

What distinguishes this campaign is the meticulous preparation exhibited by the threat actors.

The malicious domain e-library[.]wiki was registered in March 2025 over six months before the phishing emails were sent a deliberate strategy to establish domain reputation and circumvent email spam filters.

The attackers even hosted a replica of the legitimate eLibrary homepage, demonstrating extensive reconnaissance of their targets’ typical workflows and trusted resources.

The personalization evident throughout the campaign further underscores ForumTroll’s operational discipline.

Phishing emails were customized for individual victims, with downloaded archives bearing recipients’ names in the format LastName_FirstName_Patronymic, creating a veneer of legitimacy that would likely bypass initial security scrutiny.

Technical Sophistication

The malicious archives deployed in this campaign contained carefully crafted infection chains designed to obstruct security analysis.

A malicious shortcut file, named after each victim, triggered a PowerShell script that downloaded a payload from the attacker’s infrastructure.

Notably, the attackers implemented anti-analysis protections restricting downloads to Windows-only environments and preventing repeated file downloads mechanisms suggesting awareness of security researchers’ typical analysis methodologies.

The infection process established persistence through COM Hijacking, a technique replicating ForumTroll’s spring 2025 campaign methodology.

The final payload an OLLVM-obfuscated loader deployed the Tuoni framework, a publicly available red teaming tool that provided remote access and extensive system compromise capabilities.

While ForumTroll’s spring campaign exploited zero-day vulnerabilities for system compromise, the autumn attacks represent a tactical pivot toward social engineering.

This shift reflects a calculated approach: rather than relying on sophisticated exploit chains, the group concentrated on manipulating trusted academic resources to drive victim engagement.

Ongoing Threat Assessment

The campaign’s use of decoy plagiarism reports and the targeted nature of communications suggest ForumTroll’s operators possess detailed intelligence about their victims’ professional activities and research interests.

This intelligence-gathering capability indicates potential support from nation-state actors or well-resourced cybercriminal organizations.

Kaspersky researchers assess that ForumTroll will likely continue targeting Russian and Belarusian entities and individuals, leveraging both zero-day exploits and sophisticated social engineering campaigns.

The group’s demonstrated operational continuity since at least 2022, combined with access to commercial spyware frameworks like Dante and red teaming tools like Tuoni, positions them as a persistent and evolving threat to sensitive targets in Eastern Europe.

Organizations should prioritize security awareness training emphasizing verification of communications from trusted platforms, while security teams should monitor for ForumTroll infrastructure indicators and implement robust email authentication mechanisms.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs

Iran-linked threat actor Mirage Kitten is targeting software developers...

Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks

Threat actors are actively exploiting two newly disclosed remote...

Hackers Pose as IT Support on Microsoft Teams to Target More Than 150 Employees

A coordinated social-engineering campaign dubbed Spring Ring used external...

Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme

Five Venezuelan nationals have pleaded guilty in a federal...

Hackers Abuse Legitimate ChatGPT Shared Links to Deploy NetSupport RAT

Threat actors are abusing legitimate ChatGPT shared-conversation URLs to...

JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS

A sophisticated cryptocurrency-focused information stealer that hides its malicious...

Critical JFrog Artifactory Authentication Bypass Exploited in the Wild

Security researchers have issued warnings that attackers are actively...

Boston Scientific Cyberattack Disrupts Manufacturing and Product Shipments

Boston Scientific is working to restore its manufacturing, order...

Related Articles

Recent News