{"id":433691,"date":"2025-10-27T11:26:01","date_gmt":"2025-10-27T08:26:01","guid":{"rendered":"https:\/\/menatech.net\/en\/?p=433691"},"modified":"2025-11-11T17:02:16","modified_gmt":"2025-11-11T14:02:16","slug":"announced-at-sascon-2025-kaspersky-spots-spyware-from-a-long-dormant-hacker-group","status":"publish","type":"post","link":"https:\/\/menatech.net\/en\/announced-at-sascon-2025-kaspersky-spots-spyware-from-a-long-dormant-hacker-group\/","title":{"rendered":"Announced at SASCON 2025, Kaspersky spots spyware from a long-dormant hacker group"},"content":{"rendered":"<p style=\"font-weight: 400;\">Earlier today, Kaspersky announced that its global research and analysis team (GReAT) has uncovered evidence linking the HackingTeam successor, Memento Labs, to a new wave of cyber espionage attacks. The announcement took place on the first day of the Security Analyst Summit in Thailand, which MENA TECH is attending as the event\u2019s exclusive Middle East media partner.<\/p>\n<p style=\"font-weight: 400;\">The discovery stems from an investigation into Operation ForumTroll, an Advanced Persistent Threat (APT) campaign that exploited a zero-day vulnerability in Google Chrome.<\/p>\n<p style=\"font-weight: 400;\">In March 2025, Kaspersky GReAT <a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/kaspersky-discovers-sophisticated-chrome-zero-day-exploit-used-in-active-attacks\" rel=\"nofollow noopener\" target=\"_blank\">brought to light<\/a> Operation ForumTroll, a sophisticated cyberespionage campaign that exploited a Chrome zero-day vulnerability, CVE-2025-2783. The APT group responsible for the attack sent personalized phishing emails disguised as invitations to the Primakov Readings forum, targeting Russian media outlets,\u00a0government agencies, educational,\u00a0and financial\u00a0institutions.<\/p>\n<p style=\"font-weight: 400;\">While investigating ForumTroll, researchers identified that the attackers used a spyware called LeetAgent, which stood out because its commands were written in leetspeak\u2014a rare feature in APT malware. Further analysis revealed similarities between its toolset and a more advanced spyware that Kaspersky GReAT has observed in other attacks. After determining that, in some cases, the latter was launched by LeetAgent or that they shared a loader framework, researchers confirmed the connection between the two, as well as between the attacks.<\/p>\n<div id=\"attachment_433693\" style=\"width: 778px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-433693\" class=\"wp-image-433693 size-medium_large lazyload\" data-src=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-66-768x512.jpg\" alt=\"MENA TECH attending #theSAS2025 in Thailand\" width=\"768\" height=\"512\" data-srcset=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-66-768x512.jpg 768w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-66-300x200.jpg 300w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-66-1024x683.jpg 1024w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-66.jpg 1200w\" data-sizes=\"auto\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 768px; --smush-placeholder-aspect-ratio: 768\/512;\" data-original-sizes=\"(max-width: 768px) 100vw, 768px\" \/><p id=\"caption-attachment-433693\" class=\"wp-caption-text\">MENA TECH attending #theSAS2025 in Thailand<\/p><\/div>\n<p style=\"font-weight: 400;\">Although the other spyware used advanced anti-analysis techniques, including\u00a0VMProtect obfuscation, Kaspersky was able to find the malware\u2019s name in the code and identify it as\u00a0<em>Dante<\/em>. The researchers found that Memento Labs, the rebranded successor to HackingTeam, promoted a commercial spyware with the same name. Additionally, the latest samples of HackingTeam&#8217;s Remote Control System spyware, obtained by Kaspersky GReAT, are similar to <em>Dante<\/em>.\u00a0<\/p>\n<p style=\"font-weight: 400;\"><em>\u201cWhile the existence of spyware vendors is well-known in the industry, their products remain elusive, particularly in targeted attacks where identification is exceptionally challenging. Uncovering Dante&#8217;s origins demanded peeling back layers of heavily obfuscated code, tracing a handful of rare fingerprints across years of malware evolution, and correlating them with a corporate lineage. Maybe it is the reason they called it Dante \u2014 there\u2019s a hell of a journey for anyone who would try to find its roots,\u201d<\/em> said Boris Larin, principal security researcher at Kaspersky GReAT.<\/p>\n<div id=\"attachment_433694\" style=\"width: 778px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-433694\" class=\"wp-image-433694 size-medium_large lazyload\" data-src=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-65-768x512.jpg\" alt=\"A snippet from the Kaspersky Security Analyst Summit\" width=\"768\" height=\"512\" data-srcset=\"https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-65-768x512.jpg 768w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-65-300x200.jpg 300w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-65-1024x683.jpg 1024w, https:\/\/cdn.menatech.net\/wp-content\/uploads\/sites\/2\/2025\/10\/Untitled-design-65.jpg 1200w\" data-sizes=\"auto\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 768px; --smush-placeholder-aspect-ratio: 768\/512;\" data-original-sizes=\"(max-width: 768px) 100vw, 768px\" \/><p id=\"caption-attachment-433694\" class=\"wp-caption-text\">A snippet from the Kaspersky Security Analyst Summit<\/p><\/div>\n<p style=\"font-weight: 400;\">To avoid detection,\u00a0Dante<em>\u00a0us<\/em>es a unique approach to analyze its environment before determining whether it can safely perform its functions.<\/p>\n<p style=\"font-weight: 400;\">The researchers traced the first use of\u00a0LeetAgent\u00a0back to\u00a02022\u00a0and found more attacks by\u00a0ForumTroll APT\u00a0targeting organizations and individuals in\u00a0Russia and Belarus. The group is notable for its strong command of\u00a0Russian\u00a0and understanding of local nuances, which Kaspersky observed in other campaigns linked to this APT threat. However, occasional mistakes indicate that the attackers were not native speakers.<\/p>\n<p style=\"font-weight: 400;\">The attack leveraging LeetAgent was first detected by <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/xdr\" rel=\"nofollow noopener\" target=\"_blank\">Kaspersky Next XDR Expert<\/a>. The full details of this research, as well as future updates on ForumTroll APT and Dante, are available to customers of the APT reporting service through <a href=\"https:\/\/opentip.kaspersky.com\/\" rel=\"nofollow noopener\" target=\"_blank\">the Kaspersky Threat Intelligence Portal<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier today, Kaspersky announced that its global research and analysis team (GReAT) has uncovered evidence linking the HackingTeam successor, Memento Labs, to a new wave of cyber espionage attacks. The announcement took place on the first day of the Security Analyst Summit in Thailand, which MENA TECH is attending as the event\u2019s exclusive Middle East [&hellip;]<\/p>\n","protected":false},"author":254,"featured_media":433695,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":[],"meta":{"_acf_changed":false,"_breakdance_hide_in_design_set":false,"_breakdance_tags":"","footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[29330],"tags":[29380,29405,29415],"audience-intent":[],"content-types":[],"country":[],"entity":[],"persona":[],"class_list":["post-433691","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-cybersecurity","tag-enterprise-news","tag-russia"],"acf":[],"_links":{"self":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts\/433691","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/users\/254"}],"replies":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/comments?post=433691"}],"version-history":[{"count":0,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts\/433691\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/media\/433695"}],"wp:attachment":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/media?parent=433691"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/categories?post=433691"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/tags?post=433691"},{"taxonomy":"audience-intent","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/audience-intent?post=433691"},{"taxonomy":"content-types","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/content-types?post=433691"},{"taxonomy":"country","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/country?post=433691"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/entity?post=433691"},{"taxonomy":"format","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/format?post=433691"},{"taxonomy":"persona","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/persona?post=433691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}