ForumTrol Operation Uses Chrome Zero-Day in Fresh Phishing Attacks
The ForumTroll Advanced Persistent Threat (APT) group has launched a sophisticated phishing campaign targeting Russian academics. This marks a significant escalation in their operations against Russian and Belarusian entities.
The ForumTroll Advanced Persistent Threat (APT) group has launched a sophisticated phishing campaign targeting Russian academics. This marks a significant escalation in their operations against Russian and Belarusian entities.
Previously known for exploiting CVE-2025-2783, a zero-day vulnerability in Google Chrome, ForumTroll's latest campaign employs advanced social engineering tactics and commercial red teaming frameworks to compromise high-value targets.
Kaspersky GReAT researchers identified the new campaign in October 2025. The phishing emails impersonated eLibrary, a legitimate scientific electronic library, targeting scholars in political science, international relations, and economics at major Russian universities and research institutions.
The campaign is characterized by meticulous preparation. The domain e-library[.]wiki was registered in March 2025, over six months before the phishing emails were sent, to establish domain reputation and circumvent email spam filters. The attackers hosted a replica of the legitimate eLibrary homepage, indicating extensive reconnaissance of their targets.
Phishing emails were customized for individual recipients, with downloaded archives named in the format LastName_FirstName_Patronymic, increasing the likelihood of bypassing initial security scrutiny.
The ForumTroll Advanced Persistent Threat (APT) group has launched a sophisticated phishing campaign targeting Russian academics.
The malicious archives contained advanced infection chains designed to obstruct security analysis. A malicious shortcut file initiated a PowerShell script to download a payload from the attacker’s infrastructure. Anti-analysis protections were implemented, restricting downloads to Windows-only environments and preventing repeated file downloads.
Persistence was achieved through COM Hijacking, replicating methodologies from ForumTroll’s previous campaigns. The final payload, an OLLVM-obfuscated loader, deployed the Tuoni framework, a red teaming tool offering remote access and system compromise capabilities.
The autumn attacks represent a tactical shift towards social engineering, focusing on manipulating trusted academic resources rather than exploiting vulnerabilities.
The campaign’s use of decoy plagiarism reports and targeted communications suggests ForumTroll’s operators possess detailed intelligence on their victims' professional activities. This intelligence-gathering capability may indicate support from nation-state actors or well-resourced cybercriminal organizations.
Kaspersky researchers predict that ForumTroll will continue targeting entities in Russia and Belarus, utilizing both zero-day exploits and social engineering tactics. The group’s operational continuity since 2022, combined with access to commercial spyware frameworks and red teaming tools, positions them as a persistent threat in Eastern Europe.
Organizations are advised to prioritize security awareness training, emphasizing the verification of communications from trusted platforms. Security teams should monitor for ForumTroll infrastructure indicators and implement robust email authentication mechanisms.
Based on reporting by GBHackers.
